cbcvebase.
CVE-2012-2737
published 2012-07-22

CVE-2012-2737: The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying…

PriorityP410low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.36%
28.6th percentile
The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalaccountsservice>= 0 < 0.6.21-60.6.21-6
canonicalaccountsservice>= 0 < 0.6.21-60.6.21-6
canonicalaccountsservice>= 0 < 0.6.21-60.6.21-6
canonicalaccountsservice>= 0 < 0.6.21-60.6.21-6
debianaccountsservice< accountsservice 0.6.21-6 (bookworm)accountsservice 0.6.21-6 (bookworm)
ray_stodeaccountsservice<= 0.6.21
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice
ray_stodeaccountsservice

CVSS provenance

nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_debian1.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.