SB2019110678 - Red Hat Enterprise Linux 8 update for GNOME
Published: November 6, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Access of Uninitialized Pointer (CVE-ID: CVE-2019-11459)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due tothe TIFFReadRGBAImageOriented() function called from tiff_document_render() and tiff_document_get_thumbnail() functions in the backend/tiff/tiff-document.c in GNOME Evince returns uninitialized memory instead of false, when failing to read an image. A remote attacker can gain access to sensitive information on the system.
2) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-12795)
The vulnerability allows a local attacker to escalate privileges on the system.
The vulnerability exists due to the daemon/gvfsdaemon.c opened a private D-Bus server socket without configuring an authorization rule. A local attacker can connect to this server socket and issue D-Bus method calls.
Remediation
Install update from vendor's website.