GHSL-2023-139: Use After Free (UAF) in accountsservice - CVE-2023-3297
Published Jun 29, 2023
·Updated
An unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
Affected Software
1 affected component
Freedesktop accountsservice
Event History
Jun 29, 2023
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of GHSL-2023-139?
The severity of GHSL-2023-139 is rated at 44, indicating a significant risk level.
2
What is the impact of GHSL-2023-139?
GHSL-2023-139 allows an unprivileged local attacker to exploit a use-after-free vulnerability in accountsservice.
3
How do I fix GHSL-2023-139?
To fix GHSL-2023-139, update the accountsservice package to the latest patched version provided by your distribution.
4
What systems are affected by GHSL-2023-139?
GHSL-2023-139 affects systems using the Freedesktop accountsservice, particularly those running the vulnerable versions.
5
Who can exploit GHSL-2023-139?
An unprivileged local attacker can exploit GHSL-2023-139 by sending a specially crafted D-Bus message to the accounts-daemon process.