Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-4406
HistoryDec 20, 2011 - 12:00 a.m.

CVE-2011-4406

2011-12-2000:00:00
ubuntu.com
ubuntu.com
9

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

EPSS

0

Percentile

5.1%

The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not
properly drop privileges when changing language settings, which allows
local users to modify arbitrary files via unspecified vectors.

Bugs

Notes

Author Note
jdstrand per Robert, “I believe this is a custom Ubuntu change in accountsservice.”
OSVersionArchitecturePackageVersionFilename
ubuntu11.10noarchaccountsservice< 0.6.14-1git1ubuntu1.1UNKNOWN

CVSS2

3.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:P/A:P

EPSS

0

Percentile

5.1%