USN-6687-1: AccountsService vulnerability
Published Mar 11, 2024
·Updated
It was discovered that AccountsService called a helper incorrectly when performing password change operations. A local attacker could possibly use this issue to obtain encrypted passwords.
Affected Software
8 affected componentsFixes available
All of the following
ubuntu/accountsservice<22.07.5-2ubuntu1.5
22.07.5-2ubuntu1.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libaccountsservice0<22.07.5-2ubuntu1.5
22.07.5-2ubuntu1.5
Ubuntu Ubuntu=22.04
All of the following
ubuntu/accountsservice<0.6.55-0ubuntu12~20.04.7
0.6.55-0ubuntu12~20.04.7
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libaccountsservice0<0.6.55-0ubuntu12~20.04.7
0.6.55-0ubuntu12~20.04.7
Ubuntu Ubuntu=20.04
Event History
Mar 11, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6687-1?
The severity of USN-6687-1 is considered to be medium risk due to the potential for local attackers to obtain encrypted passwords.
2
How do I fix USN-6687-1?
To fix USN-6687-1, you should update the affected packages to their respective remedied versions provided by Ubuntu.
3
Which versions are affected by USN-6687-1?
USN-6687-1 affects Ubuntu 22.04 and 20.04 for specific versions of accountsservice and libaccountsservice0.
4
Who can exploit the vulnerability identified in USN-6687-1?
The vulnerability in USN-6687-1 can be exploited by local attackers with access to the system.
5
What is the impact of USN-6687-1?
The impact of USN-6687-1 is that it may allow local attackers to access sensitive encrypted passwords.