Rocky Linux 8 [CIQ] Security Update: gdk-pixbuf2 / gdk-pixbuf2-debuginfo / gdk-pixbuf2-debugsource / etc Multiple Vulnerabilities (crlsa-2019_3553)

high Nessus Plugin ID 355717

Synopsis

The Rocky Linux host is missing one or more security updates.

Description

The Rocky Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the CIQ crlsa-2019_3553 advisory.

* evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail() (CVE-2019-11459)

* gvfs: improper authorization in daemon/gvfsdaemon.c in gvfsd (CVE-2019-12795)

Tenable has extracted the preceding description block directly from the CIQ security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages based on the guidance in CIQ advisory crlsa-2019_3553.

See Also

https://access.redhat.com/errata/RHSA-2019:3553

https://bugzilla.redhat.com/show_bug.cgi?id=1662193

https://bugzilla.redhat.com/show_bug.cgi?id=1667136

https://bugzilla.redhat.com/show_bug.cgi?id=1673011

https://bugzilla.redhat.com/show_bug.cgi?id=1674382

https://bugzilla.redhat.com/show_bug.cgi?id=1679127

https://bugzilla.redhat.com/show_bug.cgi?id=1680164

https://bugzilla.redhat.com/show_bug.cgi?id=1685811

https://bugzilla.redhat.com/show_bug.cgi?id=1687949

https://bugzilla.redhat.com/show_bug.cgi?id=1690506

https://bugzilla.redhat.com/show_bug.cgi?id=1696708

https://bugzilla.redhat.com/show_bug.cgi?id=1698520

https://bugzilla.redhat.com/show_bug.cgi?id=1698884

https://bugzilla.redhat.com/show_bug.cgi?id=1698923

https://bugzilla.redhat.com/show_bug.cgi?id=1698929

https://bugzilla.redhat.com/show_bug.cgi?id=1698930

https://bugzilla.redhat.com/show_bug.cgi?id=1704355

https://bugzilla.redhat.com/show_bug.cgi?id=1704360

https://bugzilla.redhat.com/show_bug.cgi?id=1704378

https://bugzilla.redhat.com/show_bug.cgi?id=1705583

https://bugzilla.redhat.com/show_bug.cgi?id=1706793

https://bugzilla.redhat.com/show_bug.cgi?id=1709937

https://bugzilla.redhat.com/show_bug.cgi?id=1713080

https://bugzilla.redhat.com/show_bug.cgi?id=1713330

https://bugzilla.redhat.com/show_bug.cgi?id=1713453

https://bugzilla.redhat.com/show_bug.cgi?id=1713685

https://bugzilla.redhat.com/show_bug.cgi?id=1715738

https://bugzilla.redhat.com/show_bug.cgi?id=1715761

https://bugzilla.redhat.com/show_bug.cgi?id=1715765

https://bugzilla.redhat.com/show_bug.cgi?id=1716295

https://bugzilla.redhat.com/show_bug.cgi?id=1716771

https://bugzilla.redhat.com/show_bug.cgi?id=1718133

https://bugzilla.redhat.com/show_bug.cgi?id=1719241

https://bugzilla.redhat.com/show_bug.cgi?id=1719279

https://bugzilla.redhat.com/show_bug.cgi?id=1719779

https://bugzilla.redhat.com/show_bug.cgi?id=1720481

https://bugzilla.redhat.com/show_bug.cgi?id=1721195

https://bugzilla.redhat.com/show_bug.cgi?id=1721575

https://bugzilla.redhat.com/show_bug.cgi?id=1722047

https://bugzilla.redhat.com/show_bug.cgi?id=1722844

https://bugzilla.redhat.com/show_bug.cgi?id=1723467

https://bugzilla.redhat.com/show_bug.cgi?id=1723836

https://bugzilla.redhat.com/show_bug.cgi?id=1724551

https://bugzilla.redhat.com/show_bug.cgi?id=1725101

https://bugzilla.redhat.com/show_bug.cgi?id=1725107

https://bugzilla.redhat.com/show_bug.cgi?id=1725120

https://bugzilla.redhat.com/show_bug.cgi?id=1725555

https://bugzilla.redhat.com/show_bug.cgi?id=1725741

https://bugzilla.redhat.com/show_bug.cgi?id=1725766

https://bugzilla.redhat.com/show_bug.cgi?id=1725854

https://bugzilla.redhat.com/show_bug.cgi?id=1726093

https://bugzilla.redhat.com/show_bug.cgi?id=1726505

https://bugzilla.redhat.com/show_bug.cgi?id=1726656

https://bugzilla.redhat.com/show_bug.cgi?id=1728277

https://bugzilla.redhat.com/show_bug.cgi?id=1731372

https://bugzilla.redhat.com/show_bug.cgi?id=1735382

https://bugzilla.redhat.com/show_bug.cgi?id=1737326

https://bugzilla.redhat.com/show_bug.cgi?id=1739116

https://bugzilla.redhat.com/show_bug.cgi?id=1739117

https://bugzilla.redhat.com/show_bug.cgi?id=1741547

https://errata.build.resf.org/RLSA-2019:3553

http://www.nessus.org/u?0383f368

http://www.nessus.org/u?bf4d67c1

Plugin Details

Severity: High

ID: 355717

File Name: ciq_rocky_linux_8_crlsa-2019_3553.nasl

Version: 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 97.36

Vendor

Vendor Severity: Unknown

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2019-8689

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

CVSS Score Source: CVE-2019-8735

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/RockyLinux/release, Host/RockyLinux/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/5/2019

Vulnerability Publication Date: 1/14/2019

CISA Known Exploited Vulnerability Due Dates: 5/25/2022

Reference Information

CVE: CVE-2019-11070, CVE-2019-11459, CVE-2019-12795, CVE-2019-3820, CVE-2019-6237, CVE-2019-6251, CVE-2019-8506, CVE-2019-8518, CVE-2019-8523, CVE-2019-8524, CVE-2019-8535, CVE-2019-8536, CVE-2019-8544, CVE-2019-8551, CVE-2019-8558, CVE-2019-8559, CVE-2019-8563, CVE-2019-8571, CVE-2019-8583, CVE-2019-8584, CVE-2019-8586, CVE-2019-8587, CVE-2019-8594, CVE-2019-8595, CVE-2019-8596, CVE-2019-8597, CVE-2019-8601, CVE-2019-8607, CVE-2019-8608, CVE-2019-8609, CVE-2019-8610, CVE-2019-8611, CVE-2019-8615, CVE-2019-8619, CVE-2019-8622, CVE-2019-8623, CVE-2019-8666, CVE-2019-8671, CVE-2019-8672, CVE-2019-8673, CVE-2019-8676, CVE-2019-8677, CVE-2019-8679, CVE-2019-8681, CVE-2019-8686, CVE-2019-8687, CVE-2019-8689, CVE-2019-8690, CVE-2019-8726, CVE-2019-8735, CVE-2019-8768