nixpkgs/pkgs/development
worldofpeace 02ea0d3959 gvfs: fix CVE-2019-1244{7.8.9}
This is a version of #63481 for master.

CVE-2019-12447:
daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is
not used.

CVE-2019-12448:
daemon/gvfsbackendadmin.c has race conditions because the admin backend
doesn't implement query_info_on_read/write.

CVE-2019-12449:
daemon/gvfsbackendadmin.c mishandles a file's user and group ownership
during move (and copy with G_FILE_COPY_ALL_METADATA) operations
from admin:// to file:// URIs, because root privileges are unavailable.

Upstream MR: https://gitlab.gnome.org/GNOME/gvfs/merge_requests/48
2019-06-18 19:48:47 -04:00
..
androidndk-pkgs treewide: remove unused variables (#63177) 2019-06-16 19:59:05 +00:00
arduino treewide: remove unused variables (#63177) 2019-06-16 19:59:05 +00:00
beam-modules treewide: remove unused variables (#63177) 2019-06-16 19:59:05 +00:00
bower-modules/generic
compilers ponyc: 0.28.0 -> 0.28.1 2019-06-18 18:21:56 +02:00
coq-modules coqPackages.coqprime: enable for Coq 8.10 2019-06-18 07:29:11 +00:00
dhall-modules
dotnet-modules/patches
em-modules/generic
go-modules buildGoModule: pre-initialize module cache (#61967) 2019-05-24 09:10:35 -07:00
go-packages
guile-modules
haskell-modules treewide: remove unused variables (#63177) 2019-06-16 19:59:05 +00:00
idris-modules
interpreters Merge pull request #63295 from ehamberg/patch-2 2019-06-18 18:17:29 +02:00
java-modules treewide: remove unused variables (#63177) 2019-06-16 19:59:05 +00:00
libraries gvfs: fix CVE-2019-1244{7.8.9} 2019-06-18 19:48:47 -04:00
lisp-modules
lua-modules treewide: remove unused variables (#63177) 2019-06-16 19:59:05 +00:00
misc treewide: update cargoSha256 hashes for cargo-vendor upgrade 2019-06-01 15:17:52 +00:00
mobile treewide: remove unused variables (#63177) 2019-06-16 19:59:05 +00:00
node-packages node2nix: 1.6.0 -> 1.7.0 and regenerate all Nix expressions, introduce nodePackages_12_x attribute set 2019-06-05 23:48:42 +02:00
ocaml-modules ocamlPackages.mlgmpidl: 1.2.8 -> 1.2.10 2019-06-17 06:32:34 +00:00
perl-modules
pharo treewide: remove unused variables (#63177) 2019-06-16 19:59:05 +00:00
pure-modules
python-modules Merge pull request #63387 from r-ryantm/auto-update/python3.7-py3status 2019-06-18 17:34:29 -04:00
r-modules rPackages.git2r: Use system libgit2 2019-06-14 10:05:07 -05:00
ruby-modules treewide: remove unused variables (#63177) 2019-06-16 19:59:05 +00:00
tools Merge pull request #63253 from r-ryantm/auto-update/git-ftp 2019-06-18 13:29:18 -07:00
web treewide: fixup evaluation of updater scripts 2019-06-18 13:10:23 +02:00