In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
2023-09-01T21:15:07.977
2024-11-21T08:16:57.257
Modified
CVSSv3.1: 8.1 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | canonical | accountsservice | < 23.13.9-2ubuntu2 | Yes |
| Operating System | linux | linux_kernel | - | No |
| Application | canonical | accountsservice | < 22.08.8-1ubuntu7.1 | Yes |
| Operating System | canonical | ubuntu_linux | 23.04 | No |
| Application | canonical | accountsservice | < 22.08.8-1ubuntu7.1 | Yes |
| Operating System | canonical | ubuntu_linux | 22.10 | No |
| Application | canonical | accountsservice | < 22.07.5-2ubuntu1.4 | Yes |
| Operating System | canonical | ubuntu_linux | 22.04 | No |
| Application | canonical | accountsservice | < 0.6.55-0ubuntu12\~20.04.6 | Yes |
| Operating System | canonical | ubuntu_linux | 20.04 | No |
| Operating System | canonical | ubuntu_linux | 20.04 | Yes |
| Operating System | canonical | ubuntu_linux | 22.04 | Yes |
| Operating System | canonical | ubuntu_linux | 22.10 | Yes |
| Operating System | canonical | ubuntu_linux | 23.04 | Yes |