Format: 1.8 Date: Fri, 05 Jul 2019 09:04:54 -0400 Source: gvfs Binary: gvfs gvfs-daemons gvfs-libs gvfs-common gvfs-fuse gvfs-backends gvfs-bin Architecture: armhf armhf_translations Version: 1.36.1-0ubuntu1.3.3 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: gvfs - userspace virtual filesystem - GIO module gvfs-backends - userspace virtual filesystem - backends gvfs-bin - userspace virtual filesystem - binaries gvfs-common - userspace virtual filesystem - common data files gvfs-daemons - userspace virtual filesystem - servers gvfs-fuse - userspace virtual filesystem - fuse server gvfs-libs - userspace virtual filesystem - private libraries Changes: gvfs (1.36.1-0ubuntu1.3.3) bionic-security; urgency=medium . * SECURITY UPDATE: file ownership mishandling - debian/patches/CVE-2019-12447-1.patch: allow changing file owner in daemon/gvfsbackendadmin.c. - debian/patches/CVE-2019-12447-2.patch: use fsuid to ensure correct file ownership in daemon/gvfsbackendadmin.c. - CVE-2019-12447 * SECURITY UPDATE: race conditions in admin backend - debian/patches/CVE-2019-12448.patch: add query_info_on_read/write functionality in daemon/gvfsbackendadmin.c. - CVE-2019-12448 * SECURITY UPDATE: user and group ownership mishandling during move - debian/patches/CVE-2019-12449.patch: ensure correct ownership when moving to file:// uri in daemon/gvfsbackendadmin.c. - CVE-2019-12449 * SECURITY UPDATE: incorrect D-Bus server socket restrictions - debian/patches/CVE-2019-12795-1.patch: check that the connecting client is the same user in daemon/gvfsdaemon.c. - debian/patches/CVE-2019-12795-2.patch: only accept EXTERNAL authentication in daemon/gvfsdaemon.c. - CVE-2019-12795 Checksums-Sha1: 345341fbc1d2a679b668afc8875872911269a14e 1511368 gvfs-backends-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb b6595e8864dc56fb2e9d8573df15cf5d8c8b9e8d 265616 gvfs-backends_1.36.1-0ubuntu1.3.3_armhf.deb ace328b783a8c36173f7e16778905cdd7af6c14a 5008 gvfs-bin_1.36.1-0ubuntu1.3.3_armhf.deb 9be90e8fbb06e69cab24a72d89236c22d5be8691 451936 gvfs-daemons-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb f6ac7d7c225d99302f8cba2cc9ea1bfe05dce1bc 95552 gvfs-daemons_1.36.1-0ubuntu1.3.3_armhf.deb 2d222dfd2a7cc3e74f83069ca89e4dee578f4ff9 373780 gvfs-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb 8ebd9086dac2d5d48551298dee28e8789ae87a70 39108 gvfs-fuse-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb 74887fc9cf9918afe67cc0c9338acfb87ecdc56e 15676 gvfs-fuse_1.36.1-0ubuntu1.3.3_armhf.deb 571722fb21e7b590043e7806979405bd7bbcc487 420952 gvfs-libs-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb 25c412fd76fbe34867c79a4748a4ed1d7a91242b 76020 gvfs-libs_1.36.1-0ubuntu1.3.3_armhf.deb f77b5b463e1d0deb3f57b366b5aaad74451ec876 24905 gvfs_1.36.1-0ubuntu1.3.3_armhf.buildinfo 77da1ba218655c12bc98cc2d4fefe72beb5d4e72 93312 gvfs_1.36.1-0ubuntu1.3.3_armhf.deb 8ec2ac8bf938b037e8609ddeeb867e2bf84d2ef2 1573990 gvfs_1.36.1-0ubuntu1.3.3_armhf_translations.tar.gz Checksums-Sha256: 8fdade1568e36ffcf33f6ab1f568919e7e4d29dcdcc76cdfc807e4575ba6c588 1511368 gvfs-backends-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb 2628981319fab377f25f29d7c51ba500bdb2966a38dd75a52d2f86301f2423d3 265616 gvfs-backends_1.36.1-0ubuntu1.3.3_armhf.deb ffa1295656cd2154943c7a432ace604faed3ecc0b929c5b23fad1b54baf15e2a 5008 gvfs-bin_1.36.1-0ubuntu1.3.3_armhf.deb 2a37eae3caebb92c1c78a4e613a79d63466a0a533f04fa7735cd87f86f179747 451936 gvfs-daemons-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb 87244ed8fbaca775bceb9a726f5f9bb1f1ceac2f9878e9ec0796bc61cedabbb5 95552 gvfs-daemons_1.36.1-0ubuntu1.3.3_armhf.deb fad9403aafb6dc2ddedf82eb2adcbe9955cc7f537f86918fec863dcad56e3494 373780 gvfs-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb 1dd81bec1b0ec7649ece023aca7e4654afb2211555ba74c7afe053bcdd0a6048 39108 gvfs-fuse-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb 1c7d79e05404a5748ecbb5614ce0ba7cbf423fcc416d3f60a9c8124c58429685 15676 gvfs-fuse_1.36.1-0ubuntu1.3.3_armhf.deb 89e7df3a33d3aa52ddb3e4334daac58ce0ec35af6f0f8ccea044a8ec26748e94 420952 gvfs-libs-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb 6307670ce1c9d9f8f66f60042c37e69ba627d9ae1b72a694922c05341361d809 76020 gvfs-libs_1.36.1-0ubuntu1.3.3_armhf.deb 5765cf1c13c7b80c934b7c5aa5976f6e047f27e781e70b3bf6b4eb14509ae43c 24905 gvfs_1.36.1-0ubuntu1.3.3_armhf.buildinfo b9e7cffd09950b16cad9d50cddc68070f3a719f0052bb7f8b62177a973795791 93312 gvfs_1.36.1-0ubuntu1.3.3_armhf.deb a9e4a74af98602e0d78176cda166ab90f4bdaf72df49182794cbc7c58e2dcd50 1573990 gvfs_1.36.1-0ubuntu1.3.3_armhf_translations.tar.gz Files: 8cc9250e288275d572ea3ac80985cfbf 1511368 debug optional gvfs-backends-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb 44bb8c06cffabaa6c8e44eceaecd1573 265616 gnome optional gvfs-backends_1.36.1-0ubuntu1.3.3_armhf.deb 84fb6b7e66da8110b73a27e73d41a4a8 5008 gnome optional gvfs-bin_1.36.1-0ubuntu1.3.3_armhf.deb cb4eb42a0c82ffbbce23d79558035477 451936 debug optional gvfs-daemons-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb 63b6c8b9dc1e98296c6ae39a9e770315 95552 libs optional gvfs-daemons_1.36.1-0ubuntu1.3.3_armhf.deb fe8da343215df8467e89c209f87669ca 373780 debug optional gvfs-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb db7cf6fa119cab96340ceec4d47eaa53 39108 debug optional gvfs-fuse-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb b53b38b78992d7cf01f65b94b3617ea6 15676 gnome optional gvfs-fuse_1.36.1-0ubuntu1.3.3_armhf.deb ca7a6a6640389ec81c267c4891ee6225 420952 debug optional gvfs-libs-dbgsym_1.36.1-0ubuntu1.3.3_armhf.ddeb 9b4f89a09231aff6f9bc0a04c07955c1 76020 libs optional gvfs-libs_1.36.1-0ubuntu1.3.3_armhf.deb 75f9f4545323f9686d1cb73c2d5dc1ab 24905 gnome optional gvfs_1.36.1-0ubuntu1.3.3_armhf.buildinfo cb804322eed4912cc5e547c3c4d5d028 93312 libs optional gvfs_1.36.1-0ubuntu1.3.3_armhf.deb 8e01f86ea023d6cd132a282f3a005e04 1573990 raw-translations - gvfs_1.36.1-0ubuntu1.3.3_armhf_translations.tar.gz Original-Maintainer: Debian GNOME Maintainers