An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with GFILECOPYALLMETADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1225.0,
"function_hash": "231020120805253815594800467972206124585"
},
"signature_version": "v1",
"source": "https://gitlab.gnome.org/GNOME/gvfs@409619412e11be146a31b9a99ed965925f1aabb8",
"target": {
"file": "daemon/gvfsbackendadmin.c",
"function": "g_vfs_backend_admin_class_init"
},
"id": "CVE-2019-12449-42bca7d7"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"188400266217883493317486595327510648447",
"84370787118236718112280869999792270972",
"235841846821089703407745877082633987750",
"22225832117781730001295094493184023477",
"10481938479286945038407544721119377788",
"223840719794277329878536154385692187910",
"85960072603906379813090528892411735538"
],
"threshold": 0.9
},
"signature_version": "v1",
"source": "https://gitlab.gnome.org/GNOME/gvfs@409619412e11be146a31b9a99ed965925f1aabb8",
"target": {
"file": "daemon/gvfsbackendadmin.c"
},
"id": "CVE-2019-12449-e6d26694"
}
]