cbcvebase.
CVE-2020-16127
published 2020-11-11

CVE-2020-16127: An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.41%
33.1th percentile
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location.

Affected

10 ranges
VendorProductVersion rangeFixed in
canonicalaccountsservice>= 0 < 0.6.40-2ubuntu11.60.6.40-2ubuntu11.6
canonicalaccountsservice>= 0 < 0.6.45-1ubuntu1.30.6.45-1ubuntu1.3
canonicalaccountsservice>= 0 < 0.6.55-0ubuntu12~20.04.40.6.55-0ubuntu12~20.04.4
debianaccountsservice
freedesktopaccountsservice< 0.6.550.6.55
freedesktopaccountsservice>= 0.6.35-0ubuntu7.3 < 0.6.35-0ubuntu7.3+esm20.6.35-0ubuntu7.3+esm2
freedesktopaccountsservice>= 0.6.40-2ubuntu11 < 0.6.40-2ubuntu11.60.6.40-2ubuntu11.6
freedesktopaccountsservice>= 0.6.45-1ubuntu1 < 0.6.45-1ubuntu1.30.6.45-1ubuntu1.3
freedesktopaccountsservice>= 0.6.55-0ubuntu < 0.6.55-0ubuntu12~20.04.40.6.55-0ubuntu12~20.04.4
freedesktopaccountsservice>= 0.6.55-0ubuntu13 < 0.6.55-0ubuntu13.20.6.55-0ubuntu13.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_ubuntu6.5MEDIUM
vendor_debian2.8LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.