CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Canonical 2Accountsservice Ubuntu LinuxJun 17, 2026 Mar 25, 2025 N/A· v4 5.5 MEDIUM· v3 N/A· v2 accountsservice no longer drops permissions when writting .pam_environment |
1Canonical 2Accountsservice Ubuntu LinuxJun 17, 2026 Sep 1, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process. |
1Canonical 2Accountsservice Ubuntu LinuxJun 17, 2026 Nov 17, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized...Show more |
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors. |