CVE-2012-6655: Low severity Accountsservice Project Accountsservice vulnerability
An issue exists AccountService 0.6.37 in the userchangepasswordauthorizedcb() function in user.c which could let a local users obtain encrypted passwords.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-6655?
The severity of CVE-2012-6655 is low, with a severity value of 3.3.
How can a local user obtain encrypted passwords in AccountService 0.6.37?
A local user can obtain encrypted passwords in AccountService 0.6.37 through the user_change_password_authorized_cb() function in user.c.
Which software versions are affected by CVE-2012-6655?
AccountService versions 0.6.37 to 0.6.55-3 are affected. Debian Linux versions 8.0 to 10.0 and Redhat Enterprise Linux version 7.0 are also affected.
How can I fix CVE-2012-6655?
To fix CVE-2012-6655, update to a version of AccountService that is higher than 0.6.55-3. If you are using Debian Linux or Redhat Enterprise Linux, make sure to update to a version higher than the affected versions.
Where can I find more information about CVE-2012-6655?
You can find more information about CVE-2012-6655 at the following references: [link1], [link2], [link3].