VDB
CVE-2020-16126
CVE-2020-16126
PUBLISHED
CVSS 3.299999952316284 LOW
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from handling D-Bus messages in a timely fashion.
EPSS 0.54% · 43.3th percentile
Risk Scores
CVSS 3.1
3.299999952316284
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.54%
43.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:20.04:LTS | accountsservice | 0.6.55-0ubuntu10, 0.6.55-0ubuntu12~20.04.2, 0.6.55-0ubuntu12~20.04.1 |
| Ubuntu:Pro:14.04:LTS | accountsservice | 0.6.35-0ubuntu3, 0.6.35-0ubuntu4, 0.6.35-0ubuntu5 |
| Ubuntu:18.04:LTS | accountsservice | 0.6.42-0ubuntu3, 0.6.42-0ubuntu4, 0 |
| Ubuntu:16.04:LTS | accountsservice | 0.6.40-2ubuntu11.2, 0.6.40-2ubuntu8, 0.6.40-2ubuntu7 |
Timeline
- Nov 3, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- May 2, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
- Jan 9, 2023 EPSS Score
- Mar 13, 2023 EPSS Score
- May 14, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-16126 third-party-advisory
- https://ubuntu.com/security/notices/USN-4616-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-4616-2 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-16126 third-party-advisory