CVE-2012-2737

The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
1.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
VendorProductVersion
ray_stodeaccountsservice
𝑥
≤ 0.6.21
ray_stodeaccountsservice
0.4
ray_stodeaccountsservice
0.5
ray_stodeaccountsservice
0.6
ray_stodeaccountsservice
0.6.1
ray_stodeaccountsservice
0.6.2
ray_stodeaccountsservice
0.6.3
ray_stodeaccountsservice
0.6.4
ray_stodeaccountsservice
0.6.5
ray_stodeaccountsservice
0.6.6
ray_stodeaccountsservice
0.6.7
ray_stodeaccountsservice
0.6.8
ray_stodeaccountsservice
0.6.9
ray_stodeaccountsservice
0.6.10
ray_stodeaccountsservice
0.6.11
ray_stodeaccountsservice
0.6.12
ray_stodeaccountsservice
0.6.13
ray_stodeaccountsservice
0.6.14
ray_stodeaccountsservice
0.6.15
ray_stodeaccountsservice
0.6.16
ray_stodeaccountsservice
0.6.17
ray_stodeaccountsservice
0.6.18
ray_stodeaccountsservice
0.6.19
ray_stodeaccountsservice
0.6.20
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
accountsservice
bullseye
0.6.55-3
fixed
bookworm
22.08.8-6
fixed
sid
23.13.9-7
fixed
trixie
23.13.9-7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
accountsservice
quantal
Fixed 0.6.15-2ubuntu10
released
precise
Fixed 0.6.15-2ubuntu9.1
released
oneiric
Fixed 0.6.14-1git1ubuntu1.2
released
natty
ignored
lucid
dne
hardy
dne
References