nixpkgs/pkgs
worldofpeace fae9e165bb gvfs: fix CVE-2019-12795
This is a version of #63481 for master.

Vulnerability Description:
daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before
1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without
configuring an authorization rule. A local attacker could connect to this server
socket and issue D-Bus method calls. Note that the server socket only accepts
a single connection, so the attacker would have to discover the server and connect
to the socket before its owner does.

#63301
2019-06-18 19:48:47 -04:00
..
applications Merge pull request #63455 from r-ryantm/auto-update/vlc 2019-06-18 17:33:07 -04:00
build-support Merge pull request #63349 from seppeljordan/update-nix-prefetch-github 2019-06-18 18:11:58 -04:00
common-updater common-updater-scripts: simplify fetchgit fix 2019-06-02 09:31:51 +02:00
data Merge pull request #63249 from r-ryantm/auto-update/spleen 2019-06-17 20:47:33 -05:00
desktops epiphany: 3.32.2 -> 3.32.3 (#63244) 2019-06-17 00:47:36 +02:00
development gvfs: fix CVE-2019-12795 2019-06-18 19:48:47 -04:00
games Merge pull request #63263 from r-ryantm/auto-update/gzdoom 2019-06-17 05:52:32 -07:00
misc Merge pull request #63044 from JohnAZoidberg/wine-fonts 2019-06-17 19:39:52 +00:00
os-specific treewide: fixup evaluation of updater scripts 2019-06-18 13:10:23 +02:00
servers Merge pull request #63436 from r-ryantm/auto-update/squid 2019-06-18 19:56:54 +00:00
shells treewide: remove unused variables (#63177) 2019-06-16 19:59:05 +00:00
stdenv treewide: remove unused variables (#63177) 2019-06-16 19:59:05 +00:00
test treewide: remove unused variables (#63177) 2019-06-16 19:59:05 +00:00
tools Merge pull request #63460 from r-ryantm/auto-update/whois 2019-06-18 17:30:55 -04:00
top-level freecad: python3, qt5, occt7 (#63348) 2019-06-18 22:00:23 +02:00