Skip to content
Commit d8c9138b authored by Simon McVittie's avatar Simon McVittie Committed by Ondrej Holy
Browse files

gvfsdaemon: Check that the connecting client is the same user



Otherwise, an attacker who learns the abstract socket address from
netstat(8) or similar could connect to it and issue D-Bus method
calls.

Signed-off-by: default avatarSimon McVittie <smcv@collabora.com>
parent ec939a01
  • Author Developer

    CVE-2019-12795 has been assigned for the vulnerability fixed by this commit.

0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment