CVE-2012-2737

The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
1.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
Affected Products (NVD)
VendorProductVersion
ray_stodeaccountsservice
𝑥
≤ 0.6.21
ray_stodeaccountsservice
0.4
ray_stodeaccountsservice
0.5
ray_stodeaccountsservice
0.6
ray_stodeaccountsservice
0.6.1
ray_stodeaccountsservice
0.6.2
ray_stodeaccountsservice
0.6.3
ray_stodeaccountsservice
0.6.4
ray_stodeaccountsservice
0.6.5
ray_stodeaccountsservice
0.6.6
ray_stodeaccountsservice
0.6.7
ray_stodeaccountsservice
0.6.8
ray_stodeaccountsservice
0.6.9
ray_stodeaccountsservice
0.6.10
ray_stodeaccountsservice
0.6.11
ray_stodeaccountsservice
0.6.12
ray_stodeaccountsservice
0.6.13
ray_stodeaccountsservice
0.6.14
ray_stodeaccountsservice
0.6.15
ray_stodeaccountsservice
0.6.16
ray_stodeaccountsservice
0.6.17
ray_stodeaccountsservice
0.6.18
ray_stodeaccountsservice
0.6.19
ray_stodeaccountsservice
0.6.20
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
accountsservice
bookworm
22.08.8-6
fixed
bullseye
0.6.55-3
fixed
sid
23.13.9-7
fixed
trixie
23.13.9-7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
accountsservice
hardy
dne
lucid
dne
natty
ignored
oneiric
Fixed 0.6.14-1git1ubuntu1.2
released
precise
Fixed 0.6.15-2ubuntu9.1
released
quantal
Fixed 0.6.15-2ubuntu10
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
accountsservice
suse enterprise desktop 15
0.6.45-4.28
fixed
suse enterprise desktop 15 SP1
0.6.45-6.10.1
fixed
suse enterprise sap 12 SP5
0.6.42-16.3.1
fixed
suse enterprise sap 15
0.6.45-4.28
fixed
suse enterprise sap 15 SP1
0.6.45-6.10.1
fixed
suse enterprise server 12 SP2
0.6.42-14.2
fixed
suse enterprise server 12 SP3
0.6.42-14.2
fixed
suse enterprise server 12 SP4
0.6.42-16.3.1
fixed
suse enterprise server 12 SP5
0.6.42-16.3.1
fixed
suse enterprise server 15
0.6.45-4.28
fixed
suse enterprise server 15 SP1
0.6.45-6.10.1
fixed
accountsservice-devel
suse enterprise desktop 15
0.6.45-4.28
fixed
suse enterprise desktop 15 SP1
0.6.45-6.10.1
fixed
suse enterprise sap 15
0.6.45-4.28
fixed
suse enterprise sap 15 SP1
0.6.45-6.10.1
fixed
suse enterprise server 15
0.6.45-4.28
fixed
suse enterprise server 15 SP1
0.6.45-6.10.1
fixed
accountsservice-lang
suse enterprise desktop 15
0.6.45-4.28
fixed
suse enterprise desktop 15 SP1
0.6.45-6.10.1
fixed
suse enterprise sap 12 SP5
0.6.42-16.3.1
fixed
suse enterprise sap 15
0.6.45-4.28
fixed
suse enterprise sap 15 SP1
0.6.45-6.10.1
fixed
suse enterprise server 12 SP2
0.6.42-14.2
fixed
suse enterprise server 12 SP3
0.6.42-14.2
fixed
suse enterprise server 12 SP4
0.6.42-16.3.1
fixed
suse enterprise server 12 SP5
0.6.42-16.3.1
fixed
suse enterprise server 15
0.6.45-4.28
fixed
suse enterprise server 15 SP1
0.6.45-6.10.1
fixed
libaccountsservice0
suse enterprise desktop 15
0.6.45-4.28
fixed
suse enterprise desktop 15 SP1
0.6.45-6.10.1
fixed
suse enterprise sap 12 SP5
0.6.42-16.3.1
fixed
suse enterprise sap 15
0.6.45-4.28
fixed
suse enterprise sap 15 SP1
0.6.45-6.10.1
fixed
suse enterprise server 12 SP2
0.6.42-14.2
fixed
suse enterprise server 12 SP3
0.6.42-14.2
fixed
suse enterprise server 12 SP4
0.6.42-16.3.1
fixed
suse enterprise server 12 SP5
0.6.42-16.3.1
fixed
suse enterprise server 15
0.6.45-4.28
fixed
suse enterprise server 15 SP1
0.6.45-6.10.1
fixed
typelib-1_0-AccountsService-1_0
suse enterprise desktop 15
0.6.45-4.28
fixed
suse enterprise desktop 15 SP1
0.6.45-6.10.1
fixed
suse enterprise sap 12 SP5
0.6.42-16.3.1
fixed
suse enterprise sap 15
0.6.45-4.28
fixed
suse enterprise sap 15 SP1
0.6.45-6.10.1
fixed
suse enterprise server 12 SP2
0.6.42-14.2
fixed
suse enterprise server 12 SP3
0.6.42-14.2
fixed
suse enterprise server 12 SP4
0.6.42-16.3.1
fixed
suse enterprise server 12 SP5
0.6.42-16.3.1
fixed
suse enterprise server 15
0.6.45-4.28
fixed
suse enterprise server 15 SP1
0.6.45-6.10.1
fixed
References