Описание
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 23.13.9-8ubuntu7 |
| esm-infra-legacy/trusty | released | 0.6.35-0ubuntu7.3+esm4 |
| esm-infra-legacy/xenial | released | 0.6.40-2ubuntu11.6+esm2 |
| esm-infra/bionic | released | 0.6.45-1ubuntu1.3+esm2 |
| esm-infra/focal | released | 0.6.55-0ubuntu12~20.04.7+esm1 |
| jammy | released | 22.07.5-2ubuntu1.6 |
| noble | released | 23.13.9-2ubuntu6.1 |
| resolute | released | 23.13.9-8ubuntu5.2 |
| upstream | needs-triage |
Показывать по
7.8 High
CVSS3
Связанные уязвимости
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.
The Ubuntu-specific language helper scripts (save-to-pam-env, update-l ...
The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement expression, allowing an attacker to inject a sed 'e' flag and arbitrary shell commands that execute with the privileges of the AccountsService helper process (real UID 0) via the SetLanguage D-Bus method.
7.8 High
CVSS3