CVE-2011-4406: Low severity Canonical Accountsservice vulnerability
Published Apr 16, 2014
·Updated
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.
Affected Software
2 affected components
Canonical Accountsservice<=0.6.14
Canonical Ubuntu Linux=11.10
Remediation
Event History
Apr 16, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:37 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-4406?
CVE-2011-4406 is considered to have a medium severity level due to the potential for local users to modify arbitrary files.
2
How do I fix CVE-2011-4406?
To fix CVE-2011-4406, upgrade the AccountsService package to version 0.6.14-1git1ubuntu1.1 or later.
3
Who is affected by CVE-2011-4406?
CVE-2011-4406 affects users of the AccountsService package prior to version 0.6.14 on Ubuntu 11.10.
4
What type of vulnerability is CVE-2011-4406?
CVE-2011-4406 is a local privilege escalation vulnerability due to improper handling of language settings.
5
What versions are vulnerable in regards to CVE-2011-4406?
Versions of AccountsService prior to 0.6.14 are vulnerable to CVE-2011-4406.