Accountsservice
by Canonical
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-3297 | Hig | 0.53 | 8.1 | 0.00 | Sep 1, 2023 | In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process. | ||
| CVE-2021-3939 | Hig | 0.51 | 7.8 | 0.00 | Nov 17, 2021 | Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus… | ||
| CVE-2022-1804 | Med | 0.36 | 5.5 | 0.00 | Mar 25, 2025 | accountsservice no longer drops permissions when writting .pam_environment | ||
| CVE-2011-4406 | 0.00 | — | 0.00 | Apr 16, 2014 | The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors. |
- risk 0.53cvss 8.1epss 0.00
In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
- risk 0.51cvss 7.8epss 0.00
Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus…
- risk 0.36cvss 5.5epss 0.00
accountsservice no longer drops permissions when writting .pam_environment
- CVE-2011-4406Apr 16, 2014risk 0.00cvss —epss 0.00
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.