CVE-2023-3297: GHSL-2023-139: Use After Free (UAF) in accountsservice - CVE-2023-3297
An unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-3297?
CVE-2023-3297 is a use-after-free vulnerability in Ubuntu's accountsservice that can be triggered by an unprivileged local attacker.
What is the severity of CVE-2023-3297?
CVE-2023-3297 has a severity rating of 7.8 (high).
How does CVE-2023-3297 impact Ubuntu's accountsservice?
CVE-2023-3297 allows an unprivileged local attacker to trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
Which versions of accountsservice are affected by CVE-2023-3297?
Versions 0.6.55-0ubuntu12~20.04.6, 22.07.5-2ubuntu1.4, 22.08.8-1ubuntu1.1, and 22.08.8-1ubuntu7.1 of accountsservice are affected by CVE-2023-3297.
How can I fix CVE-2023-3297?
To fix CVE-2023-3297, update accountsservice to version 0.6.55-0ubuntu12~20.04.6, 22.07.5-2ubuntu1.4, 22.08.8-1ubuntu1.1, or 22.08.8-1ubuntu7.1 depending on your Ubuntu version.