LWN.net Logo

accountsservice: file permission bypass

Package(s):accountsservice CVE #(s):CVE-2012-2737
Created:June 29, 2012 Updated:April 8, 2013
Description:

From the Ubuntu advisory:

Florian Weimer discovered that AccountsService incorrectly handled privileges when copying certain files to the system cache directory. A local attacker could exploit this issue to read arbitrary files, bypassing intended permissions.

Alerts:
Ubuntu USN-1485-1 2012-06-28
Fedora FEDORA-2012-10120 2012-07-02
openSUSE openSUSE-SU-2012:0845-1 2012-07-06
Mageia MGASA-2012-0153 2012-07-10
Mandriva MDVSA-2013:060 2013-04-08

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds