CVE-2019-13012
Summary
| CVE | CVE-2019-13012 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-28 15:15:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently, it does not properly restrict directory (and file) permissions. Instead, for directories, 0777 permissions are used; for files, default file permissions are used. This is similar to CVE-2019-12450. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 1866-1] glib2.0 security update | MLIST | lists.debian.org | |
| [bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| [SECURITY] [DLA 1866-2] glib2.0 regression update | MLIST | lists.debian.org | |
| USN-4049-2: GLib vulnerability | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| #931234 - glib2.0: CVE-2019-13012: keyfile settings backend: Consider tightening permissions - Debian Bug report logs | CONFIRM | bugs.debian.org | |
| USN-4049-1: GLib vulnerability | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| CVE-2019-13012 GNOME GLib Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Settings portal (!450) · Merge Requests · GNOME / GLib · GitLab | MISC | gitlab.gnome.org | Issue Tracking, Third Party Advisory |
| Pony Mail! | MLIST | lists.apache.org | |
| [bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8 | lists.apache.org | ||
| keyfile settings: Use tighter permissions (5e4da714) · Commits · GNOME / GLib · GitLab | MISC | gitlab.gnome.org | Patch, Third Party Advisory |
| [security-announce] openSUSE-SU-2019:1749-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| keyfile settings backend: Consider tightening permissions (#1658) · Issues · GNOME / GLib · GitLab | MISC | gitlab.gnome.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159189 Oracle Enterprise Linux Security Update for GNOME (ELSA-2021-1586)
- 239335 Red Hat Update for GNOME (RHSA-2021:1586)
- 354922 Amazon Linux Security Advisory for glib2 : ALAS-2023-1742
- 377338 Alibaba Cloud Linux Security Update for glib2 (ALINUX3-SA-2021:0055)
- 900016 CBL-Mariner Linux Security Update for glib 2.58.0
- 902850 Common Base Linux Mariner (CBL-Mariner) Security Update for glib (1921)
- 940249 AlmaLinux Security Update for GNOME (ALSA-2021:1586)