IT

Tracker / CVE-2023-3297

CVE-2023-3297

High 8.1

In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.

Affected products and versions

canonical accountsservice · … → 0.6.55-0ubuntu12\~20.04.6
canonical accountsservice · … → 22.07.5-2ubuntu1.4
canonical accountsservice · … → 22.08.8-1ubuntu7.1
canonical accountsservice · … → 23.13.9-2ubuntu2
canonical ubuntu_linux

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References