Format: 1.8 Date: Fri, 05 Jul 2019 08:31:52 -0400 Source: gvfs Binary: gvfs gvfs-backends gvfs-bin gvfs-daemons gvfs-fuse gvfs-libs Architecture: armhf armhf_translations Version: 1.40.1-1ubuntu1 Distribution: eoan-proposed Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: gvfs - userspace virtual filesystem - GIO module gvfs-backends - userspace virtual filesystem - backends gvfs-bin - userspace virtual filesystem - deprecated command-line tools gvfs-daemons - userspace virtual filesystem - servers gvfs-fuse - userspace virtual filesystem - fuse server gvfs-libs - userspace virtual filesystem - private libraries Changes: gvfs (1.40.1-1ubuntu1) eoan; urgency=medium . * SECURITY UPDATE: file ownership mishandling - debian/patches/CVE-2019-12447-1.patch: allow changing file owner in daemon/gvfsbackendadmin.c. - debian/patches/CVE-2019-12447-2.patch: use fsuid to ensure correct file ownership in daemon/gvfsbackendadmin.c. - CVE-2019-12447 * SECURITY UPDATE: race conditions in admin backend - debian/patches/CVE-2019-12448.patch: add query_info_on_read/write functionality in daemon/gvfsbackendadmin.c. - CVE-2019-12448 * SECURITY UPDATE: user and group ownership mishandling during move - debian/patches/CVE-2019-12449.patch: ensure correct ownership when moving to file:// uri in daemon/gvfsbackendadmin.c. - CVE-2019-12449 * SECURITY UPDATE: incorrect D-Bus server socket restrictions - debian/patches/CVE-2019-12795-1.patch: check that the connecting client is the same user in daemon/gvfsdaemon.c. - debian/patches/CVE-2019-12795-2.patch: only accept EXTERNAL authentication in daemon/gvfsdaemon.c. - CVE-2019-12795 Checksums-Sha1: a28c013b808e82d747bbfc099228741fdce1aac5 1800888 gvfs-backends-dbgsym_1.40.1-1ubuntu1_armhf.ddeb a34ee7b4fce0e6c3e18160829bcb06e412adbf9e 277912 gvfs-backends_1.40.1-1ubuntu1_armhf.deb 313367fdc07ead891ee3915361d11263f66e41f5 4916 gvfs-bin_1.40.1-1ubuntu1_armhf.deb 6cc323a4bc2cd8547760d0043a2a86757ed18be1 520544 gvfs-daemons-dbgsym_1.40.1-1ubuntu1_armhf.ddeb 1de5a78617f3492e47f6d0bdbbe9bb3c5350d0de 95532 gvfs-daemons_1.40.1-1ubuntu1_armhf.deb 3180cfa17088e968c562c60aaf5d2875704f6e1b 438068 gvfs-dbgsym_1.40.1-1ubuntu1_armhf.ddeb 0d3e2365df00b52f98131d130dcd5beee8bbd472 44364 gvfs-fuse-dbgsym_1.40.1-1ubuntu1_armhf.ddeb c4ff68b7ccb4c0c41012f059463a6d17316afcaa 15368 gvfs-fuse_1.40.1-1ubuntu1_armhf.deb dca33265ff132a340c795ca57345eff615a838d3 474204 gvfs-libs-dbgsym_1.40.1-1ubuntu1_armhf.ddeb 22fb64a2b38b741e00a27e5d9b9cd45006d603bf 76044 gvfs-libs_1.40.1-1ubuntu1_armhf.deb 4d6033c0bea578a88d0a3f94318decbfd0ac27a1 24237 gvfs_1.40.1-1ubuntu1_armhf.buildinfo b2bec272640ae02253a13d9b2a94b4e298240429 95028 gvfs_1.40.1-1ubuntu1_armhf.deb 733e6babc16993c21217bdb2f2909b041938b993 1568468 gvfs_1.40.1-1ubuntu1_armhf_translations.tar.gz Checksums-Sha256: dfaf9912ccbd5f1a5babb9e63d0318418fdf8c65a1e4133eab02ae940f02af26 1800888 gvfs-backends-dbgsym_1.40.1-1ubuntu1_armhf.ddeb ba2f8552934cc6ab03e3b1f7fffd9c9a33b2d83a320ac6afba92499fc3c8b45f 277912 gvfs-backends_1.40.1-1ubuntu1_armhf.deb 8fbe9eb117b6dc9f893935bd6b3b2d87849f86cf8409cceb951373b2a25501b1 4916 gvfs-bin_1.40.1-1ubuntu1_armhf.deb dc2163d5b7e73017f0880de06c72a4d2ff01d00d32d8e2bf70e923cf50195851 520544 gvfs-daemons-dbgsym_1.40.1-1ubuntu1_armhf.ddeb 429b0680b97005cca99a361d23a7a1828e4f4cd6058ac062007abf8a3fcc006c 95532 gvfs-daemons_1.40.1-1ubuntu1_armhf.deb a550642aa36928f4c198b3301e898d95afd285bbea4422b606ec67d02b463e86 438068 gvfs-dbgsym_1.40.1-1ubuntu1_armhf.ddeb f95a211afd697e002e554ba645c57a446d7d4ec39e138d29ff85f813c43edf69 44364 gvfs-fuse-dbgsym_1.40.1-1ubuntu1_armhf.ddeb b956c12dcee035687752f35ef265677e35f87845c4d0cf3af109e3485012fc1b 15368 gvfs-fuse_1.40.1-1ubuntu1_armhf.deb c1875b6c47d5144dbb424f4bb09587e0bdd8549dd23dc85cb4f0590890e944e7 474204 gvfs-libs-dbgsym_1.40.1-1ubuntu1_armhf.ddeb 208fcf3e21ac6b8393acf98763fa556c66997c4bfda9a25b1ad1dc512338aab5 76044 gvfs-libs_1.40.1-1ubuntu1_armhf.deb cc26a67bf4b11bf05ad725b198ad57daedf6e26eb03bf6be7ebe3b727eecf95c 24237 gvfs_1.40.1-1ubuntu1_armhf.buildinfo d7c308b09c47466392abb6cbb34edae0feebd4ed024b136792f49ed2fc408a5e 95028 gvfs_1.40.1-1ubuntu1_armhf.deb a128a68895207be58a7cbfeb9b09d4b5985c1e66f6ba2837fef7707419bee07d 1568468 gvfs_1.40.1-1ubuntu1_armhf_translations.tar.gz Files: 2ae113c17825fbdb5ef3cf0658c096db 1800888 debug optional gvfs-backends-dbgsym_1.40.1-1ubuntu1_armhf.ddeb d7d6748c94012cde287ae55b4ee09877 277912 gnome optional gvfs-backends_1.40.1-1ubuntu1_armhf.deb 85fdd1499be019551e08730c769ab218 4916 oldlibs optional gvfs-bin_1.40.1-1ubuntu1_armhf.deb 8e414785bbca37efa83b85b55b471428 520544 debug optional gvfs-daemons-dbgsym_1.40.1-1ubuntu1_armhf.ddeb d7d891668e71bb629ea5f90d4b6b9564 95532 libs optional gvfs-daemons_1.40.1-1ubuntu1_armhf.deb 9e8af3faa4541dcfe03386b0bfba5ac8 438068 debug optional gvfs-dbgsym_1.40.1-1ubuntu1_armhf.ddeb 17686a951fa3dae6d807a4cc40bf816b 44364 debug optional gvfs-fuse-dbgsym_1.40.1-1ubuntu1_armhf.ddeb cc2ec3c19272767a0155c1ebd821bbea 15368 gnome optional gvfs-fuse_1.40.1-1ubuntu1_armhf.deb 9db3ac99e198be22cb5b99c84de0d9ac 474204 debug optional gvfs-libs-dbgsym_1.40.1-1ubuntu1_armhf.ddeb fb05e2368df21c2005e88d87325943a1 76044 libs optional gvfs-libs_1.40.1-1ubuntu1_armhf.deb 922e702cbe116dd7391cdc01ae19340d 24237 gnome optional gvfs_1.40.1-1ubuntu1_armhf.buildinfo 2cf23ef61b1ca1513613648cf5c0bbce 95028 libs optional gvfs_1.40.1-1ubuntu1_armhf.deb 2cae813464a59d9914f028290b8c3c22 1568468 raw-translations - gvfs_1.40.1-1ubuntu1_armhf_translations.tar.gz Original-Maintainer: Debian GNOME Maintainers