CVE-2019-12450

Related Vulnerabilities: CVE-2019-12450  

Impact: Important Public Date: 2019-05-23 CWE: CWE-552 Bugzilla: 1719141: CVE-2019-12450 glib2: file_copy_fallback in gio/gfile.c in GNOME GLib does not properly restrict file permissions while a copy operation is in progress file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.

The MITRE CVE dictionary describes this issue as:

file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.

Find out more about CVE-2019-12450 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 8.1
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity Impact High
Availability Impact None

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 8 mingw-glib2 Under investigation
Red Hat Enterprise Linux 8 glib2 Under investigation
Red Hat Enterprise Linux 7 glib2 Under investigation
Red Hat Enterprise Linux 6 firefox Under investigation
Red Hat Enterprise Linux 6 thunderbird Under investigation
Red Hat Enterprise Linux 6 chromium-browser Under investigation
Red Hat Enterprise Linux 6 glib2 Under investigation
Red Hat Enterprise Linux 5 glib2 Under investigation