First published: Wed Apr 16 2014(Updated: )
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
AccountsService | <=0.6.14 | |
Ubuntu | =11.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4406 is considered to have a medium severity level due to the potential for local users to modify arbitrary files.
To fix CVE-2011-4406, upgrade the AccountsService package to version 0.6.14-1git1ubuntu1.1 or later.
CVE-2011-4406 affects users of the AccountsService package prior to version 0.6.14 on Ubuntu 11.10.
CVE-2011-4406 is a local privilege escalation vulnerability due to improper handling of language settings.
Versions of AccountsService prior to 0.6.14 are vulnerable to CVE-2011-4406.