Описание
incomplete privilege dropping when calling SetLanguage
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 23.13.9-8ubuntu7 |
| esm-infra-legacy/trusty | released | 0.6.35-0ubuntu7.3+esm4 |
| esm-infra-legacy/xenial | released | 0.6.40-2ubuntu11.6+esm2 |
| esm-infra/bionic | released | 0.6.45-1ubuntu1.3+esm2 |
| esm-infra/focal | released | 0.6.55-0ubuntu12~20.04.7+esm1 |
| jammy | released | 22.07.5-2ubuntu1.6 |
| noble | released | 23.13.9-2ubuntu6.1 |
| resolute | released | 23.13.9-8ubuntu5.2 |
| upstream | needs-triage |
Показывать по
EPSS
7.8 High
CVSS3
Связанные уязвимости
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 on ...
An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits ruid=0 and may reset its effective UID to root, enabling local privilege escalation.
EPSS
7.8 High
CVSS3