// For flags

CVE-2012-2737

 

Severity Score

4.7
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.

La función de user_change_icon_file_authorized_cb en /usr/libexec/accounts-daemon de las cuentas en AccountsService anterior a v0.6.22 no comprueba correctamente el UID al copiar un archivo de icono en el directorio de memoria caché del sistema, lo que permite a usuarios locales leer ficheros arbitrarios a través de una condición de carrera.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-05-14 CVE Reserved
  • 2012-07-22 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
<= 0.6.21
Search vendor "Ray Stode" for product "Accountsservice" and version " <= 0.6.21"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.4
Search vendor "Ray Stode" for product "Accountsservice" and version "0.4"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.5
Search vendor "Ray Stode" for product "Accountsservice" and version "0.5"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.1
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.1"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.2
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.2"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.3
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.3"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.4
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.4"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.5
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.5"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.6
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.6"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.7
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.7"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.8
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.8"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.9
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.9"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.10
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.10"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.11
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.11"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.12
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.12"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.13
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.13"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.14
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.14"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.15
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.15"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.16
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.16"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.17
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.17"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.18
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.18"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.19
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.19"
-
Affected
Ray Stode
Search vendor "Ray Stode"
Accountsservice
Search vendor "Ray Stode" for product "Accountsservice"
0.6.20
Search vendor "Ray Stode" for product "Accountsservice" and version "0.6.20"
-
Affected