cbcvebase.
CVE-2011-4406
published 2014-04-16

CVE-2011-4406: The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to…

PriorityP413low3.6CVSS 2.0
AVLACLAuNCNIPAP
EPSS
0.38%
30.1th percentile
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.

Affected

7 ranges
VendorProductVersion rangeFixed in
canonicalaccountsservice<= 0.6.14
canonicalaccountsservice>= 0 < 0.6.15-30.6.15-3
canonicalaccountsservice>= 0 < 0.6.15-30.6.15-3
canonicalaccountsservice>= 0 < 0.6.15-30.6.15-3
canonicalaccountsservice>= 0 < 0.6.15-30.6.15-3
canonicalubuntu_linux
debianaccountsservice< accountsservice 0.6.15-3 (bookworm)accountsservice 0.6.15-3 (bookworm)

CVSS provenance

nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.6LOW
vendor_debian3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.