VendorsRay Stodeaccountsservice0.6.10
Vulnerabilities

Ray Stode Ray Strode AccountsService 0.6.10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2012-2737
The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.
Published 2012-07-22 · Modified
1.9EPSS 0.004