First published: Wed Jun 28 2023(Updated: )
Kevin Backhouse discovered that AccountsService incorrectly handled certain D-Bus messages. A local attacker could use this issue to cause AccountsService to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/accountsservice | <22.08.8-1ubuntu7.1 | 22.08.8-1ubuntu7.1 |
=23.04 | ||
All of | ||
ubuntu/libaccountsservice0 | <22.08.8-1ubuntu7.1 | 22.08.8-1ubuntu7.1 |
=23.04 | ||
All of | ||
ubuntu/accountsservice | <22.08.8-1ubuntu1.1 | 22.08.8-1ubuntu1.1 |
=22.10 | ||
All of | ||
ubuntu/libaccountsservice0 | <22.08.8-1ubuntu1.1 | 22.08.8-1ubuntu1.1 |
=22.10 | ||
All of | ||
ubuntu/accountsservice | <22.07.5-2ubuntu1.4 | 22.07.5-2ubuntu1.4 |
=22.04 | ||
All of | ||
ubuntu/libaccountsservice0 | <22.07.5-2ubuntu1.4 | 22.07.5-2ubuntu1.4 |
=22.04 | ||
All of | ||
ubuntu/accountsservice | <0.6.55-0ubuntu12~20.04.6 | 0.6.55-0ubuntu12~20.04.6 |
=20.04 | ||
All of | ||
ubuntu/libaccountsservice0 | <0.6.55-0ubuntu12~20.04.6 | 0.6.55-0ubuntu12~20.04.6 |
=20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this AccountsService vulnerability is USN-6190-1.
The vulnerability allows a local attacker to cause AccountsService to crash, resulting in a denial of service, or possibly execute arbitrary code.
The affected software versions include accountsservice 22.08.8-1ubuntu7.1, libaccountsservice0 22.08.8-1ubuntu7.1, accountsservice 22.08.8-1ubuntu1.1, libaccountsservice0 22.08.8-1ubuntu1.1, accountsservice 22.07.5-2ubuntu1.4, libaccountsservice0 22.07.5-2ubuntu1.4, accountsservice 0.6.55-0ubuntu12~20.04.6, and libaccountsservice0 0.6.55-0ubuntu12~20.04.6.
To fix this vulnerability, update the affected software to the recommended version provided by the vendor.
More information about this vulnerability can be found at the following references: https://ubuntu.com/security/CVE-2023-3297, https://launchpad.net/ubuntu/+source/accountsservice/22.08.8-1ubuntu7.1, https://launchpad.net/ubuntu/+source/accountsservice/22.08.8-1ubuntu1.1