← Back

Accountsservice

accountsservice

Vendor: Canonical • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Canonical
2Accountsservice
Ubuntu Linux
Jun 17, 2026
Mar 25, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
accountsservice no longer drops permissions when writting .pam_environment
1Canonical
2Accountsservice
Ubuntu Linux
Jun 17, 2026
Sep 1, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
1Canonical
2Accountsservice
Ubuntu Linux
Jun 17, 2026
Nov 17, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized...Show more
Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus function. This is fixed in versions 0.6.55-0ubuntu12~20.04.5, 0.6.55-0ubuntu13.3, 0.6.55-0ubuntu14.1.Show less
1Canonical
2Accountsservice
Ubuntu Linux
May 6, 2026
Apr 16, 2014
N/A· v4
N/A· v3
3.6 LOW· v2
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.