CVE-2012-2737
EPSS 0.36%
Description
The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.
How to fix CVE-2012-2737
To remediate CVE-2012-2737, upgrade the affected package to a fixed version below.
- Debian/accountsservice—upgrade to 0.6.21-6 or later
Is CVE-2012-2737 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.6.21-6