CVE-2019-11461 (https://nvd.nist.gov/vuln/detail/CVE-2019-11461): An issue was discovered in GNOME Nautilus 3.30 prior to 3.30.6 and 3.32 prior to 3.32.1. A compromised thumbnailer may escape the bubblewrap sandbox used to confine thumbnailers by using the TIOCSTI ioctl to push characters into the input buffer of the thumbnailer's controlling terminal, allowing an attacker to escape the sandbox if the thumbnailer has a controlling terminal. This is due to improper filtering of the TIOCSTI ioctl on 64-bit systems, similar to CVE-2019-10063.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=85cb57ebc68ef86e7286050d8edc186c3f632cf2 commit 85cb57ebc68ef86e7286050d8edc186c3f632cf2 Author: Mart Raudsepp <leio@gentoo.org> AuthorDate: 2019-08-23 20:57:09 +0000 Commit: Mart Raudsepp <leio@gentoo.org> CommitDate: 2019-08-23 20:57:09 +0000 gnome-base/nautilus: fix CVE-2019-11461 Bug: https://bugs.gentoo.org/692784 Package-Manager: Portage-2.3.62, Repoman-2.3.12 Signed-off-by: Mart Raudsepp <leio@gentoo.org> .../nautilus/files/3.30.5-CVE-2019-11461.patch | 30 ++++++ gnome-base/nautilus/nautilus-3.30.5-r1.ebuild | 106 +++++++++++++++++++++ 2 files changed, 136 insertions(+)
arm64 stable
amd64 stable
x86 stable. Maintainer(s), please cleanup. Security, please add it to the existing request, or file a new one.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=91a58bac644b1715b23214bd4977d1bdec7bcea2 commit 91a58bac644b1715b23214bd4977d1bdec7bcea2 Author: Mart Raudsepp <leio@gentoo.org> AuthorDate: 2019-08-31 14:05:47 +0000 Commit: Mart Raudsepp <leio@gentoo.org> CommitDate: 2019-08-31 14:05:54 +0000 gnome-base/nautilus: security cleanup Bug: https://bugs.gentoo.org/692784 Package-Manager: Portage-2.3.69, Repoman-2.3.12 Signed-off-by: Mart Raudsepp <leio@gentoo.org> gnome-base/nautilus/Manifest | 2 - gnome-base/nautilus/files/3.28.1-docs-build.patch | 42 --------- gnome-base/nautilus/nautilus-3.28.1.ebuild | 104 --------------------- gnome-base/nautilus/nautilus-3.30.5.ebuild | 105 ---------------------- 4 files changed, 253 deletions(-)
*** Bug 685850 has been marked as a duplicate of this bug. ***
This issue was resolved and addressed in GLSA 201908-27 at https://security.gentoo.org/glsa/201908-27 by GLSA coordinator Thomas Deutschmann (whissi).