CVE-2011-4406
Publication date 20 December 2011
Last updated 24 July 2024
Ubuntu priority
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.
Status
Package | Ubuntu Release | Status |
---|---|---|
accountsservice | 11.10 oneiric |
Fixed 0.6.14-1git1ubuntu1.1
|
11.04 natty |
Not affected
|
|
10.10 maverick | Not in release | |
10.04 LTS lucid | Not in release | |
8.04 LTS hardy | Not in release |
Notes
References
Related Ubuntu Security Notices (USN)
- USN-1351-1
- AccountsService vulnerability
- 31 January 2012