Skip to content
Commit e3808a1b authored by Simon McVittie's avatar Simon McVittie Committed by Ondrej Holy
Browse files

gvfsdaemon: Check that the connecting client is the same user



Otherwise, an attacker who learns the abstract socket address from
netstat(8) or similar could connect to it and issue D-Bus method
calls.

Signed-off-by: default avatarSimon McVittie <smcv@collabora.com>
parent bed1e968
Loading
Loading
Loading
Loading
  • Author Developer

    CVE-2019-12795 has been assigned for the vulnerability fixed by this commit.

0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment