Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2012-2737 Details

Description

The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://cgit.freedesktop.org/accountsservice/commit/?id=26213aa0e0d8dca5f36cc23f6942525224cbe9f5 CVEExploitPatch
http://cgit.freedesktop.org/accountsservice/commit/?id=27f3d93a82fde4f6c7ab54f3f008af04f93f9c69 CVE
http://cgit.freedesktop.org/accountsservice/commit/?id=4c5b12e363410e490e776e4b4a86dcce157a543d CVEExploitPatch
http://cgit.freedesktop.org/accountsservice/commit/?id=bd51aa4cdac380f55d607f4ffdf2ab3c00d08721 CVEExploitPatch
http://lists.fedoraproject.org/pipermail/package-announce/2012-July/083359.html CVE

see all 28 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')[email protected]

Affected Products

ProductVersions
ray stode accountsservice
<= 0.6.21
0.4
0.5
0.6
0.6.1

CPE

  • cpe:2.3:a:ray_stode:accountsservice:*:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.4:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.5:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.1:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.2:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.3:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.4:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.5:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.6:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.7:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.8:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.9:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.10:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.11:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.12:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.13:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.14:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.15:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.16:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.17:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.18:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.19:*:*:*:*:*:*:*
  • cpe:2.3:a:ray_stode:accountsservice:0.6.20:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2012-2737
NVD Published Date:
Jul 22, 2012
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2012-2737 Details - Not Deferred