CVE-2011-4406
published 2014-04-16CVE-2011-4406: The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to…
PriorityP413low3.6CVSS 2.0
AVLACLAuNCNIPAP
EPSS
0.38%
30.1th percentile
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | accountsservice | <= 0.6.14 | — |
| canonical | accountsservice | >= 0 < 0.6.15-3 | 0.6.15-3 |
| canonical | accountsservice | >= 0 < 0.6.15-3 | 0.6.15-3 |
| canonical | accountsservice | >= 0 < 0.6.15-3 | 0.6.15-3 |
| canonical | accountsservice | >= 0 < 0.6.15-3 | 0.6.15-3 |
| canonical | ubuntu_linux | — | — |
| debian | accountsservice | < accountsservice 0.6.15-3 (bookworm) | accountsservice 0.6.15-3 (bookworm) |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv3.6LOW
vendor_debian3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hg97-5vhj-mp5w: The Ubuntu AccountsService package before 0
ghsa_unreviewed·2022-05-17
CVE-2011-4406 [LOW] GHSA-hg97-5vhj-mp5w: The Ubuntu AccountsService package before 0
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.
OSV
CVE-2011-4406: The Ubuntu AccountsService package before 0
osv·2014-04-16·CVSS 3.6
CVE-2011-4406 [LOW] CVE-2011-4406: The Ubuntu AccountsService package before 0
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.
Ubuntu
AccountsService vulnerability
vendor_ubuntu·2012-01-31
CVE-2011-4406 AccountsService vulnerability
Title: AccountsService vulnerability
Summary: AccountsService could be made to overwrite files as the administrator.
Hayawardh Vijayakumar discovered that AccountsService incorrectly handled
privileges when modifying the language settings on Ubuntu. A local attacker
could exploit this issue to modify arbitrary files, and possibly create a
denial of service or obtain increased privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2011-4406: accountsservice - The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properl...
vendor_debian·2011·CVSS 3.6
CVE-2011-4406 [LOW] CVE-2011-4406: accountsservice - The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properl...
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.6.15-3)
bullseye: resolved (fixed in 0.6.15-3)
forky: resolved (fixed in 0.6.15-3)
sid: resolved (fixed in 0.6.15-3)
trixie: resolved (fixed in 0.6.15-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bazaar.launchpad.net/~ubuntu-branches/ubuntu/oneiric/accountsservice/oneiric-updates/revision/21http://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-4406.htmlhttp://www.ubuntu.com/usn/USN-1351-1http://bazaar.launchpad.net/~ubuntu-branches/ubuntu/oneiric/accountsservice/oneiric-updates/revision/21http://people.canonical.com/~ubuntu-security/cve/2011/CVE-2011-4406.htmlhttp://www.ubuntu.com/usn/USN-1351-1
2014-04-16
Published