CVE编号
CVE-2019-12450利用情况
暂无补丁情况
官方补丁披露时间
2019-05-30漏洞描述
GNOME GLib 2.15.0 through 2.61.1中的gio / gfile.c中的file_copy_fallback在复制操作正在进行时未正确限制文件权限。而是使用默认权限。解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接 |
|
---|---|
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00076.html | |
https://access.redhat.com/errata/RHSA-2019:3530 | |
https://gitlab.gnome.org/GNOME/glib/commit/d8f8f4d637ce43f8699ba94c9b7648beda0ca174 | |
https://lists.debian.org/debian-lts-announce/2019/06/msg00013.html | |
https://lists.fedoraproject.org/archives/list/[email protected]... | |
https://security.netapp.com/advisory/ntap-20190606-0003/ | |
https://usn.ubuntu.com/4014-1/ | |
https://usn.ubuntu.com/4014-2/ |
受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
应用 | gnome | glib | * |
From (including) 2.15.0 |
Up to (including) 2.61.1 |
||||
运行在以下环境 | |||||||||
系统 | alibaba_cloud_linux_2.1903 | glib | * |
Up to (excluding) 2.56.1-7.1.al7 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.10 | glib | * |
Up to (excluding) 2.60.4-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.11 | glib | * |
Up to (excluding) 2.60.4-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.12 | glib | * |
Up to (excluding) 2.60.4-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.13 | glib | * |
Up to (excluding) 2.60.4-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.14 | glib | * |
Up to (excluding) 2.60.4-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.15 | glib | * |
Up to (excluding) 2.60.4-r0 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.7 | glib | * |
Up to (excluding) 2.54.2-r1 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.8 | glib | * |
Up to (excluding) 2.56.1-r1 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_3.9 | glib | * |
Up to (excluding) 2.58.1-r3 |
|||||
运行在以下环境 | |||||||||
系统 | alpine_edge | glib | * |
Up to (excluding) 2.60.4-r0 |
|||||
运行在以下环境 | |||||||||
系统 | amazon_2 | glib | * |
Up to (excluding) 2.56.1-4.amzn2 |
|||||
运行在以下环境 | |||||||||
系统 | amazon_AMI | glib | * |
Up to (excluding) 2.36.3-5.21.amzn1 |
|||||
运行在以下环境 | |||||||||
系统 | centos_8 | glib | * |
Up to (excluding) 2.56.4-7.el8 |
|||||
运行在以下环境 | |||||||||
系统 | debian_8 | glib | * |
Up to (excluding) 2.42.1-1+deb8u1 |
|||||
运行在以下环境 | |||||||||
系统 | debian_9 | glib | * |
Up to (excluding) 2.50.3-2+deb9u1 |
|||||
运行在以下环境 | |||||||||
系统 | fedora_30 | glib | * |
Up to (excluding) 2.60.4-1.fc30 |
|||||
运行在以下环境 | |||||||||
系统 | opensuse_Leap_15.0 | glib | * |
Up to (excluding) 0-2.54.3-lp150.3.10.1 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_7 | glib | * |
Up to (excluding) 2.56.1-7.el7 |
|||||
运行在以下环境 | |||||||||
系统 | oracle_8 | glib | * |
Up to (excluding) 2.56.4-7.el8 |
|||||
运行在以下环境 | |||||||||
系统 | redhat_8 | glib | * |
Up to (excluding) 2.56.4-7.el8 |
|||||
运行在以下环境 | |||||||||
系统 | suse_12_SP3 | glib | * |
Up to (excluding) 2.48.2-12.12.2 |
|||||
运行在以下环境 | |||||||||
系统 | suse_12_SP4 | glib | * |
Up to (excluding) 2.48.2-12.12.2 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_14.04 | glib | * |
Up to (excluding) 2.40.2-0ubuntu1.1+esm1 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_16.04 | glib | * |
Up to (excluding) 2.48.2-0ubuntu4.2 |
|||||
运行在以下环境 | |||||||||
系统 | ubuntu_18.04 | glib | * |
Up to (excluding) 2.56.4-0ubuntu0.18.04.3 |
|||||
- 攻击路径 本地
- 攻击复杂度 困难
- 权限要求 普通权限
- 影响范围 有限影响
- EXP成熟度 未验证
- 补丁情况 官方补丁
- 数据保密性 无影响
- 数据完整性 无影响
- 服务器危害 无影响
- 全网数量 -
还没有评论,来说两句吧...