cbcvebase.
CVE-2011-4406
published 2014-04-16

CVE-2011-4406: The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to…

low3.6CVSS 3.1
AVLACLAuNCNIPAP
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.

Affected

7 ranges
VendorProductVersion rangeFixed in
canonicalaccountsservice<= 0.6.14
canonicalaccountsservice>= 0 < 0.6.15-30.6.15-3
canonicalaccountsservice>= 0 < 0.6.15-30.6.15-3
canonicalaccountsservice>= 0 < 0.6.15-30.6.15-3
canonicalaccountsservice>= 0 < 0.6.15-30.6.15-3
canonicalubuntu_linux
debianaccountsservice< accountsservice 0.6.15-3 (bookworm)accountsservice 0.6.15-3 (bookworm)

CVSS provenance

nvd3.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.6LOW