VDB

CVE-2023-3297

CVE-2023-3297 PUBLISHED CVSS 8.100000381469727 HIGH

In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.

EPSS 0.33% · 25.5th percentile

Risk Scores

CVSS 3.1
8.100000381469727
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.33%
25.5th percentile

Affected Products

VendorProductVersions
canonicalaccountsservice0, 0, 0
Canonical Ltd.AccountService23.13.9-2ubuntu2, 23.13.9-2ubuntu2
canonicalubuntu_linux20.04, 22.04, 23.04

Timeline

  • Sep 1, 2023 CVE Published
  • Sep 2, 2023 EPSS Score
  • Sep 2, 2023 PoC Published
  • Oct 5, 2023 EPSS Score
  • Nov 7, 2023 EPSS Score
  • Dec 9, 2023 EPSS Score
  • Jan 11, 2024 EPSS Score
  • Feb 13, 2024 EPSS Score
  • Mar 17, 2024 EPSS Score
  • Apr 19, 2024 EPSS Score
  • May 22, 2024 EPSS Score
  • Jun 23, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›