Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

1 – 9 of 9 results


CVE-2023-3297

Medium priority
Fixed

In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.

1 affected packages

accountsservice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
accountsservice Fixed Fixed Fixed Fixed
Show less packages

CVE-2022-1804

Medium priority
Fixed

accountsservice no longer drops permissions when writing .pam_environment

1 affected packages

accountsservice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
accountsservice Fixed Not affected Not affected Not affected
Show less packages

CVE-2021-3939

High priority
Fixed

Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb...

1 affected packages

accountsservice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
accountsservice Fixed Fixed Not affected Not affected
Show less packages

CVE-2020-16127

Medium priority
Fixed

An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop...

1 affected packages

accountsservice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
accountsservice Fixed Not affected Not affected
Show less packages

CVE-2020-16126

Medium priority
Fixed

An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from...

1 affected packages

accountsservice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
accountsservice Fixed Fixed Fixed
Show less packages

CVE-2012-6655

Low priority

Some fixes available 2 of 20

An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.

1 affected packages

accountsservice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
accountsservice Not affected Fixed Fixed Vulnerable Vulnerable
Show less packages

CVE-2018-14036

Low priority

Some fixes available 3 of 6

Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.

1 affected packages

accountsservice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
accountsservice Not affected Fixed Fixed
Show less packages

CVE-2012-2737

Medium priority

Some fixes available 3 of 4

The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to...

1 affected packages

accountsservice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
accountsservice
Show less packages

CVE-2011-4406

High priority
Fixed

The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.

1 affected packages

accountsservice

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
accountsservice
Show less packages