CVE-2019-12449
MEDIUMOpensuse Leap < 1.41.2 - Improper Exception Handling
Title source: ruleDescription
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with G_FILE_COPY_ALL_METADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.
References (7)
Scores
CVSS v3
5.7
EPSS
0.0060
EPSS Percentile
69.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Classification
CWE
CWE-755
Status
published
Affected Products (9)
opensuse/leap
opensuse/leap
gnome/gvfs
< 1.41.2
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
fedoraproject/fedora
fedoraproject/fedora
Timeline
Published
May 29, 2019
Tracked Since
Feb 18, 2026