VDB
CVE-2023-3297
CVE-2023-3297
PUBLISHED
CVSS 8.100000381469727 HIGH
In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
EPSS 0.33% · 25.5th percentile
Risk Scores
CVSS 3.1
8.100000381469727
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
0.33%
25.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| canonical | accountsservice | 0, 0, 0 |
| Canonical Ltd. | AccountService | 23.13.9-2ubuntu2, 23.13.9-2ubuntu2 |
| canonical | ubuntu_linux | 20.04, 22.04, 23.04 |
Timeline
- Sep 1, 2023 CVE Published
- Sep 2, 2023 EPSS Score
- Sep 2, 2023 PoC Published
- Oct 5, 2023 EPSS Score
- Nov 7, 2023 EPSS Score
- Dec 9, 2023 EPSS Score
- Jan 11, 2024 EPSS Score
- Feb 13, 2024 EPSS Score
- Mar 17, 2024 EPSS Score
- Apr 19, 2024 EPSS Score
- May 22, 2024 EPSS Score
- Jun 23, 2024 EPSS Score
References
- https://securitylab.github.com/advisories/GHSL-2023-139_accountsservice/ third-party-advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3297 issue
- https://nvd.nist.gov/vuln/detail/CVE-2023-3297 advisory
- https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2024182 exploit
- https://ubuntu.com/security/notices/USN-6190-1 advisory
- https://securitylab.github.com/advisories/GHSL-2023-139_accountsservice advisory