Canonical AccountsService是英国Canonical公司开源的一个提供用户账户信息查询与操作的系统服务。 Canonical AccountsService 23.13.9-8ubuntu7之前版本存在命令注入漏洞,该漏洞源于Ubuntu特定语言辅助脚本将用户控制的LANGUAGE条目视为可信输入,未转义插入GNU sed替换表达式,可能导致攻击者注入sed 'e'标志和任意shell命令,以AccountsService辅助进程权限(真实UID 0)通过SetLanguage D-
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Canonical | accountsservice | 22.07.5-2ubuntu1< 22.07.5-2ubuntu1.6 |
affected |
23.13.9-2ubuntu6< 23.13.9-2ubuntu6.1 |
affected | ||
23.13.9-8ubuntu5< 23.13.9-8ubuntu5.2 |
affected | ||
23.13.9-8ubuntu6< 23.13.9-8ubuntu7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Canonical | accountsservice | 22.07.5-2ubuntu1 ~ 22.07.5-2ubuntu1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-61897 | 7.8 HIGH | accountsservice: incomplete privilege drop when running Ubuntu-specific language helper sc |
| CVE-2026-77113 | 6.7 MEDIUM | Path Traversal Vulnerability in apport-unpack |
No comments yet