VYPR

Accountsservice

by Canonical

CVEs (4)

  • CVE-2023-3297HigSep 1, 2023
    risk 0.53cvss 8.1epss 0.00

    In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.

  • CVE-2021-3939HigNov 17, 2021
    risk 0.51cvss 7.8epss 0.00

    Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus…

  • CVE-2022-1804MedMar 25, 2025
    risk 0.36cvss 5.5epss 0.00

    accountsservice no longer drops permissions when writting .pam_environment

  • CVE-2011-4406Apr 16, 2014
    risk 0.00cvss epss 0.00

    The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.