USN-1485-1: AccountsService vulnerability
28 June 2012
AccountsService could be made to read arbitrary files as the administrator.
Releases
Packages
- accountsservice - query and manipulate user account information
Details
Florian Weimer discovered that AccountsService incorrectly handled
privileges when copying certain files to the system cache directory. A
local attacker could exploit this issue to read arbitrary files, bypassing
intended permissions.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04
Ubuntu 11.10
After a standard system update you need to reboot your computer to make
all the necessary changes.