The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.
CVSS Details
- CVSS 3.1 Base Score: 4.7
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade accountsservice | Jul 30, 2024 | Jul 22, 2012 |
| Suse | — | Upgrade accountsservice-langUpgrade accountsservice-develUpgrade typelib-1_0-AccountsService-1_0Upgrade accountsservice-valaUpgrade accountsserviceUpgrade libaccountsservice0 | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade accountsserviceUpgrade libaccountsservice0 | Nov 8, 2024 | Jul 22, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub