3.6
CVSSv2

CVE-2011-4406

Published: 16/04/2014 Updated: 17/04/2014
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

The Ubuntu AccountsService package prior to 0.6.14-1git1ubuntu1.1 does not properly drop privileges when changing language settings, which allows local users to modify arbitrary files via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 11.10

canonical accountsservice

Vendor Advisories

AccountsService could be made to overwrite files as the administrator ...