VDB
CVE-2012-2737
CVE-2012-2737
PUBLISHED
CVSS 1.899999976158142 LOW
The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.
EPSS 0.07% · 21.9th percentile
Risk Scores
CVSS 2.0
1.899999976158142
EPSS Score
0.07%
21.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| ray_stode | accountsservice | 0.4, 0.5, 0.6 |
Timeline
- Jul 22, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 17, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
References
- 54223 vdb
- http://cgit.freedesktop.org/accountsservice/commit/?id=bd51aa4cdac380f55d607f4ffdf2ab3c00d08721 url
- 49695 third-party-advisory
- USN-1485-1 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=832532 url
- 49759 third-party-advisory
- 83398 vdb
- accountsservice-userchangeicon-info-disc(76648) vdb
- openSUSE-SU-2012:0845 vendor-advisory
- http://cgit.freedesktop.org/accountsservice/commit/?id=26213aa0e0d8dca5f36cc23f6942525224cbe9f5 url
- http://cgit.freedesktop.org/accountsservice/commit/?id=27f3d93a82fde4f6c7ab54f3f008af04f93f9c69 url
- [oss-security] 20120628 accountsservice local file disclosure flaw (CVE-2012-2737) mailing-list
- FEDORA-2012-10120 vendor-advisory
- http://cgit.freedesktop.org/accountsservice/commit/?id=4c5b12e363410e490e776e4b4a86dcce157a543d url
- https://nvd.nist.gov/vuln/detail/CVE-2012-2737 advisory