Bugzilla – Bug 1212889
VUL-0: CVE-2023-3297: accountsservice: use-after-free via a D-Bus message to the accounts-daemon process
Last modified: 2023-06-30 09:15:02 UTC
CVE-2023-3297 An unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process. References: https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2024182 https://packetstormsecurity.com/files/173189/USN-6190-1.txt References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-3297 https://bugzilla.redhat.com/show_bug.cgi?id=2218566
As far as I can see this affects patches applied only in ubuntu. i quickly grepped through the code and we seem to not have those patches applied, so i will track these as not affected: - SUSE:ALP:Source:Standard:1.0/accountsservice 22.08.8 - SUSE:SLE-12-SP2:Update/accountsservice 0.6.42 - SUSE:SLE-15-SP2:Update/accountsservice 0.6.55 - SUSE:SLE-15-SP4:Update/accountsservice 0.6.55 - SUSE:SLE-15:Update/accountsservice 0.6.45 - openSUSE:Factory/accountsservice 23.13.9