Vulnerability Name:

CVE-2019-3827 (CCN-159535)

Assigned:2018-12-27
Published:2018-12-27
Updated:2020-10-19
Summary:An incorrect permission check in the admin backend in gvfs before version 1.39.4 was found that allows reading and modify arbitrary files by privileged users without asking for password when no authentication agent is running. This vulnerability can be exploited by malicious programs running under privileges of users belonging to the wheel group to further escalate its privileges by modifying system files without user's knowledge. Successful exploitation requires uncommon system configuration.
CVSS v3 Severity:7.0 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
6.1 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.0 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.1 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:3.3 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-863
CWE-863
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2019-3827

Source: REDHAT
Type: Third Party Advisory
RHSA-2019:1517

Source: REDHAT
Type: Third Party Advisory
RHSA-2019:2145

Source: CCN
Type: Red Hat Bugzilla – Bug 1665578
(CVE-2019-3827) - CVE-2019-3827 gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3827

Source: XF
Type: UNKNOWN
gnomegvfs-cve20193827-priv-esc(159535)

Source: CCN
Type: gvfs GIT Repository
GNOME gvfs

Source: CONFIRM
Type: Patch, Vendor Advisory
https://gitlab.gnome.org/GNOME/gvfs/merge_requests/31

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnome:gvfs:*:*:*:*:*:*:*:* (Version < 1.39.4)

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/a:redhat:enterprise_linux:8::crb:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*

  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20193827
    V
    CVE-2019-3827
    2023-06-22
    oval:org.opensuse.security:def:7901
    P
    gvfs-1.48.2-150400.4.6.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:747
    P
    Security update for keepalived (Important)
    2022-09-09
    oval:org.opensuse.security:def:3283
    P
    libwavpack1-4.60.99-5.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94913
    P
    gvfs-1.48.1-150400.2.17 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:1668
    P
    Security update for libslirp (Important)
    2022-05-18
    oval:org.opensuse.security:def:94024
    P
    (Important)
    2022-05-16
    oval:org.opensuse.security:def:1197
    P
    Security update for openssl-1_1 (Important)
    2022-03-16
    oval:org.opensuse.security:def:1439
    P
    Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP3) (Important)
    2022-03-01
    oval:org.opensuse.security:def:1083
    P
    Security update for tiff (Important)
    2022-02-17
    oval:org.opensuse.security:def:100737
    P
    (Moderate)
    2022-01-20
    oval:org.opensuse.security:def:112385
    P
    gvfs-1.48.1-1.3 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:69955
    P
    Security update for webkit2gtk3 (Important)
    2021-11-23
    oval:org.opensuse.security:def:1553
    P
    Security update for the Linux Kernel (Important)
    2021-11-09
    oval:org.opensuse.security:def:105896
    P
    gvfs-1.48.1-1.3 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:71234
    P
    libXi-devel-1.7.9-1.23 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:47269
    P
    gnome-settings-daemon-3.20.1-49.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47969
    P
    ceph-common-12.2.12+git.1568024032.02236657ca-2.39.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47821
    P
    libzypp-16.19.0-2.36.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47729
    P
    libjson-c2-0.11-2.15 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47268
    P
    gnome-keyring-3.20.0-27.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47597
    P
    dpdk-17.11.4-3.6 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48329
    P
    ucode-intel-20191112-1.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47404
    P
    libraptor2-0-2.0.10-3.63 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48267
    P
    perl-LWP-Protocol-https-6.04-5.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47283
    P
    gv-3.7.4-1.36 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48183
    P
    libqpdf18-7.1.1-3.3.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:2035
    P
    google-compute-engine-oslogin-20190801-4.38.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2041
    P
    python3-keystoneclient-4.0.0-9.4.5 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2037
    P
    kernel-azure-base-4.12.14-8.58.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62757
    P
    gvfs-1.42.2-4.24 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101163
    P
    gvfs-1.42.2-4.24 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72476
    P
    gvfs-1.42.2-4.24 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:67781
    P
    Security update for the Linux Kernel (Live Patch 22 for SLE 15) (Important)
    2021-07-27
    oval:org.opensuse.security:def:64534
    P
    Security update for wireshark (Important)
    2021-06-22
    oval:org.opensuse.security:def:48694
    P
    libsilc-1_1-2-1.1.10-24.128 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48569
    P
    libxcb-dri2-0-1.10-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71121
    P
    wpa_supplicant-2.6-2.50 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48394
    P
    cups-filters-1.0.58-13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48553
    P
    libsrtp1-1.5.2-2.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48496
    P
    libgnomesu-2.0.0-353.6.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48552
    P
    libsqlite3-0-3.8.10.2-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48425
    P
    ghostscript-9.15-6.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48892
    P
    argyllcms-1.6.3-3.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:51175
    P
    Security update for the Linux Kernel (Important)
    2021-03-09
    oval:org.opensuse.security:def:49127
    P
    Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork (Important)
    2021-02-12
    oval:org.opensuse.security:def:66704
    P
    Security update for slurm_17_11 (Important)
    2020-12-18
    oval:org.opensuse.security:def:64447
    P
    Security update for the Linux Kernel (Important)
    2020-12-10
    oval:org.opensuse.security:def:73395
    P
    Security update for openssl-1_1 (Important)
    2020-12-09
    oval:org.opensuse.security:def:89878
    P
    gvfs-1.34.2.1-4.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2055
    P
    bind-9.11.2-10.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62528
    P
    gvfs-1.34.2.1-4.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107403
    P
    gvfs-1.42.2-4.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2046
    P
    clamsap-0.99.25-2.37 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2092
    P
    sblim-sfcb-1.4.9-3.7 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72247
    P
    gvfs-1.34.2.1-4.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2090
    P
    rsyslog-module-gssapi-8.33.1-1.30 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62642
    P
    gvfs-1.42.2-4.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2085
    P
    openssh-fips-7.6p1-7.8 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:72361
    P
    gvfs-1.42.2-4.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2080
    P
    libwsman-devel-2.6.7-1.37 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49033
    P
    libraw9-0.15.4-30.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116961
    P
    gvfs-1.42.2-4.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2063
    P
    grub2-x86_64-xen-2.02-17.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:103533
    P
    gvfs-1.34.2.1-4.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2057
    P
    davfs2-1.5.4-1.4 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2740
    P
    Security update for gvfs (Important)
    2020-12-02
    oval:org.opensuse.security:def:2730
    P
    Security update for avahi (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:49764
    P
    xorg-x11-server-sdk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49601
    P
    texlive-12many on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:70060
    P
    gvfs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51113
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49512
    P
    firewall-applet on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49281
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49524
    P
    gvfs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73277
    P
    pam_yubico on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49733
    P
    ctags on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49470
    P
    libthai-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49638
    P
    gvfs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66612
    P
    python3-requests on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67881
    P
    gvfs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49584
    P
    libvpx-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49837
    P
    guile on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49668
    P
    libical-devel on GA media (Moderate)
    2020-12-01
    oval:com.redhat.rhsa:def:20192145
    P
    RHSA-2019:2145: gvfs security and bug fix update (Moderate)
    2019-08-06
    oval:com.redhat.rhsa:def:20191517
    P
    RHSA-2019:1517: gvfs security update (Moderate)
    2019-06-18
    oval:com.ubuntu.xenial:def:201938270000000
    V
    CVE-2019-3827 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-03-25
    oval:com.ubuntu.bionic:def:20193827000
    V
    CVE-2019-3827 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-03-25
    oval:com.ubuntu.cosmic:def:20193827000
    V
    CVE-2019-3827 on Ubuntu 18.10 (cosmic) - medium.
    2019-03-25
    oval:com.ubuntu.cosmic:def:201938270000000
    V
    CVE-2019-3827 on Ubuntu 18.10 (cosmic) - medium.
    2019-03-25
    oval:com.ubuntu.trusty:def:20193827000
    V
    CVE-2019-3827 on Ubuntu 14.04 LTS (trusty) - medium.
    2019-03-25
    oval:com.ubuntu.bionic:def:201938270000000
    V
    CVE-2019-3827 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-03-25
    oval:com.ubuntu.xenial:def:20193827000
    V
    CVE-2019-3827 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-03-25
    BACK
    gnome gvfs *