CVE-2011-4406

CWE-2646 documents6 sources
Severity
3.6LOW
EPSS
0.1%
top 83.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16
Latest updateMay 17

Description

The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.

CVSS vector

AV:L/AC:L/C:N/I:P/A:PExploitability: 3.9 | Impact: 4.9

Affected Packages2 packages

Debianaccountsservice< 0.6.15-3+3

Also affects: Ubuntu Linux 11.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-hg97-5vhj-mp5w: The Ubuntu AccountsService package before 02022-05-17
CVEList
CVE-2011-4406: The Ubuntu AccountsService package before 02014-04-16
OSV
CVE-2011-4406: The Ubuntu AccountsService package before 02014-04-16

📋Vendor Advisories

2
Ubuntu
AccountsService vulnerability2012-01-31
Debian
CVE-2011-4406: accountsservice - The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properl...2011
CVE-2011-4406 (LOW CVSS 3.6) | The Ubuntu AccountsService package | cvebase.io