Vulnerability Description
The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ray Stode | Accountsservice | <= 0.6.21 |
Related Weaknesses (CWE)
References
- http://cgit.freedesktop.org/accountsservice/commit/?id=26213aa0e0d8dca5f36cc23f6ExploitPatch
- http://cgit.freedesktop.org/accountsservice/commit/?id=27f3d93a82fde4f6c7ab54f3f
- http://cgit.freedesktop.org/accountsservice/commit/?id=4c5b12e363410e490e776e4b4ExploitPatch
- http://cgit.freedesktop.org/accountsservice/commit/?id=bd51aa4cdac380f55d607f4ffExploitPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2012-July/083359.html
- http://osvdb.org/83398
- http://secunia.com/advisories/49695Vendor Advisory
- http://secunia.com/advisories/49759Vendor Advisory
- http://www.openwall.com/lists/oss-security/2012/06/28/9
- http://www.securityfocus.com/bid/54223
- http://www.ubuntu.com/usn/USN-1485-1
- https://bugzilla.redhat.com/show_bug.cgi?id=832532
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76648
- https://hermes.opensuse.org/messages/15100967
- http://cgit.freedesktop.org/accountsservice/commit/?id=26213aa0e0d8dca5f36cc23f6ExploitPatch
FAQ
What is CVE-2012-2737?
CVE-2012-2737 is a vulnerability with a CVSS score of 1.9 (LOW). The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache director...
How severe is CVE-2012-2737?
CVE-2012-2737 has been rated LOW with a CVSS base score of 1.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-2737?
Check the references section above for vendor advisories and patch information. Affected products include: Ray Stode Accountsservice.