Vulnerability Details CVE-2019-12449
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 65.6%
CVSS Severity
CVSS v3 Score 5.7
CVSS v2 Score 3.5
Products affected by CVE-2019-12449
-
cpe:2.3:a:gnome:gvfs:1.29.4
-
cpe:2.3:a:gnome:gvfs:1.29.90
-
cpe:2.3:a:gnome:gvfs:1.29.91
-
cpe:2.3:a:gnome:gvfs:1.29.92
-
cpe:2.3:a:gnome:gvfs:1.30.0
-
cpe:2.3:a:gnome:gvfs:1.30.1
-
cpe:2.3:a:gnome:gvfs:1.30.1.1
-
cpe:2.3:a:gnome:gvfs:1.30.2
-
cpe:2.3:a:gnome:gvfs:1.30.3
-
cpe:2.3:a:gnome:gvfs:1.30.4
-
cpe:2.3:a:gnome:gvfs:1.31.1
-
cpe:2.3:a:gnome:gvfs:1.31.2
-
cpe:2.3:a:gnome:gvfs:1.31.3
-
cpe:2.3:a:gnome:gvfs:1.31.4
-
cpe:2.3:a:gnome:gvfs:1.31.90
-
cpe:2.3:a:gnome:gvfs:1.31.91
-
cpe:2.3:a:gnome:gvfs:1.31.92
-
cpe:2.3:a:gnome:gvfs:1.32.0
-
cpe:2.3:a:gnome:gvfs:1.32.1
-
cpe:2.3:a:gnome:gvfs:1.32.2
-
cpe:2.3:a:gnome:gvfs:1.33.1
-
cpe:2.3:a:gnome:gvfs:1.33.3
-
cpe:2.3:a:gnome:gvfs:1.33.90
-
cpe:2.3:a:gnome:gvfs:1.33.91
-
cpe:2.3:a:gnome:gvfs:1.33.92
-
cpe:2.3:a:gnome:gvfs:1.34.0
-
cpe:2.3:a:gnome:gvfs:1.34.1
-
cpe:2.3:a:gnome:gvfs:1.34.2
-
cpe:2.3:a:gnome:gvfs:1.34.2.1
-
cpe:2.3:a:gnome:gvfs:1.35.1
-
cpe:2.3:a:gnome:gvfs:1.35.2
-
cpe:2.3:a:gnome:gvfs:1.35.3
-
cpe:2.3:a:gnome:gvfs:1.35.4
-
cpe:2.3:a:gnome:gvfs:1.35.90
-
cpe:2.3:a:gnome:gvfs:1.35.91
-
cpe:2.3:a:gnome:gvfs:1.35.92
-
cpe:2.3:a:gnome:gvfs:1.36.0
-
cpe:2.3:a:gnome:gvfs:1.36.1
-
cpe:2.3:a:gnome:gvfs:1.36.2
-
cpe:2.3:a:gnome:gvfs:1.36.3
-
cpe:2.3:a:gnome:gvfs:1.37.1
-
cpe:2.3:a:gnome:gvfs:1.37.2
-
cpe:2.3:a:gnome:gvfs:1.37.4
-
cpe:2.3:a:gnome:gvfs:1.37.90
-
cpe:2.3:a:gnome:gvfs:1.37.91
-
cpe:2.3:a:gnome:gvfs:1.37.92
-
cpe:2.3:a:gnome:gvfs:1.38.0
-
cpe:2.3:a:gnome:gvfs:1.38.1
-
cpe:2.3:a:gnome:gvfs:1.38.2
-
cpe:2.3:a:gnome:gvfs:1.38.3
-
cpe:2.3:a:gnome:gvfs:1.39.1
-
cpe:2.3:a:gnome:gvfs:1.39.3
-
cpe:2.3:a:gnome:gvfs:1.39.4
-
cpe:2.3:a:gnome:gvfs:1.39.90
-
cpe:2.3:a:gnome:gvfs:1.39.91
-
cpe:2.3:a:gnome:gvfs:1.39.92
-
cpe:2.3:a:gnome:gvfs:1.40.0
-
cpe:2.3:a:gnome:gvfs:1.40.1
-
cpe:2.3:a:gnome:gvfs:1.40.2
-
cpe:2.3:a:gnome:gvfs:1.41.1
-
cpe:2.3:a:gnome:gvfs:1.41.2
-
cpe:2.3:o:canonical:ubuntu_linux:16.04
-
cpe:2.3:o:canonical:ubuntu_linux:18.04
-
cpe:2.3:o:canonical:ubuntu_linux:18.10
-
cpe:2.3:o:canonical:ubuntu_linux:19.04
-
cpe:2.3:o:fedoraproject:fedora:29
-
cpe:2.3:o:fedoraproject:fedora:30
-
cpe:2.3:o:opensuse:leap:15.0
-
cpe:2.3:o:opensuse:leap:15.1