An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
{ "vanir_signatures": [ { "id": "CVE-2019-12447-128da555", "signature_type": "Function", "digest": { "function_hash": "221129427121838919402311318763590252207", "length": 543.0 }, "target": { "file": "daemon/gvfsbackendadmin.c", "function": "do_query_info" }, "deprecated": false, "signature_version": "v1", "source": "https://gitlab.gnome.org/GNOME/gvfs@d7d362995aa0cb8905c8d5c2a2a4c305d2ffff80" }, { "id": "CVE-2019-12447-2c45386e", "signature_type": "Function", "digest": { "function_hash": "315758984730309787526684648289640819509", "length": 399.0 }, "target": { "file": "daemon/gvfsbackendadmin.c", "function": "do_query_info_on_read" }, "deprecated": false, "signature_version": "v1", "source": "https://gitlab.gnome.org/GNOME/gvfs@d7d362995aa0cb8905c8d5c2a2a4c305d2ffff80" }, { "id": "CVE-2019-12447-2f863eae", "signature_type": "Line", "digest": { "line_hashes": [ "73916177003641685572968591140627056112", "253018699655399886978684173833991900463", "32636196277512700844917516674410904213", "60225804736163445770261030020149093149", "295188651935798861711237930154468362773", "336949180031531535903300586715887847111", "122733523442005799036535946978199199215", "38715005556965058985949591750549156080", "190219455231647675840419608914300357934", "130958840252877500505001559892379322624", "84226649914448015677384007816104284654", "298302122726318424865405617214389136455", "193864371884430685022515345336037369450", "107778891356980170510552533430107576593", "140936156180911864638887877595746396694", "45125191213936464693370036745465389237", "193864371884430685022515345336037369450", "107778891356980170510552533430107576593", "140936156180911864638887877595746396694", "45125191213936464693370036745465389237", "193864371884430685022515345336037369450", "107778891356980170510552533430107576593", "140936156180911864638887877595746396694", "199385678116433857180824745464754018949", "308700058573000777060027644789832722692", "258936626926811761635742473922404076168", "298306042285414535072862238550100067832", "38621369527279116206907721802346232539", "247610009810254618915339530098308913622", "276737675418966760951910999472124881363" ], "threshold": 0.9 }, "target": { "file": "daemon/gvfsbackendadmin.c" }, "deprecated": false, "signature_version": "v1", "source": "https://gitlab.gnome.org/GNOME/gvfs@d7d362995aa0cb8905c8d5c2a2a4c305d2ffff80" }, { "id": "CVE-2019-12447-5d0df07e", "signature_type": "Function", "digest": { "function_hash": "315758984730309787526684648289640819509", "length": 399.0 }, "target": { "file": "daemon/gvfsbackendadmin.c", "function": "do_query_info_on_write" }, "deprecated": false, "signature_version": "v1", "source": "https://gitlab.gnome.org/GNOME/gvfs@d7d362995aa0cb8905c8d5c2a2a4c305d2ffff80" }, { "id": "CVE-2019-12447-65afe312", "signature_type": "Function", "digest": { "function_hash": "102790847050225268433877757460925083898", "length": 300.0 }, "target": { "file": "daemon/gvfsbackendadmin.c", "function": "fix_file_info" }, "deprecated": false, "signature_version": "v1", "source": "https://gitlab.gnome.org/GNOME/gvfs@d7d362995aa0cb8905c8d5c2a2a4c305d2ffff80" }, { "id": "CVE-2019-12447-b7af7425", "signature_type": "Function", "digest": { "function_hash": "320077015584121439858559977796245338654", "length": 483.0 }, "target": { "file": "daemon/gvfsbackendadmin.c", "function": "acquire_caps" }, "deprecated": false, "signature_version": "v1", "source": "https://gitlab.gnome.org/GNOME/gvfs@d7d362995aa0cb8905c8d5c2a2a4c305d2ffff80" } ] }