📦

accountsservice

Vendor: canonical

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 8 Total Indexed
Avg. EPSS 0.30% Exploit Prob.
Latest CVE CVE-2022-1804 Mar 25

Security Vulnerability Index

Page 1 / 1
5.5 CVSS

accountsservice no longer drops permissions when writting .pam_environment

EPSS: 0.14%
8.1 CVSS

In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.

EPSS: 0.33%
7.8 CVSS

Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus function. This is fixed in versions 0.6.55-0ubuntu12~20.04.5, 0.6.55-0ubuntu13.3, 0.6.55-0ubuntu14.1.

EPSS: 0.35%
3.6 CVSS

The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.

EPSS: 0.38%