Release of Invalid Pointer or Reference Affecting accountsservice package, versions <0.6.55-3ubuntu2


Severity

Recommended
0.0
high
0
10

Based on Ubuntu security rating.

Threat Intelligence

EPSS
0.16% (39th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2204-ACCOUNTSSERVICE-2783421
  • published17 Nov 2021
  • disclosed17 Nov 2021

Introduced: 17 Nov 2021

CVE-2021-3939  (opens in a new tab)
CWE-763  (opens in a new tab)

How to fix?

Upgrade Ubuntu:22.04 accountsservice to version 0.6.55-3ubuntu2 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream accountsservice package and not the accountsservice package as distributed by Ubuntu. See How to fix? for Ubuntu:22.04 relevant fixed versions and status.

Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus function. This is fixed in versions 0.6.55-0ubuntu12~20.04.5, 0.6.55-0ubuntu13.3, 0.6.55-0ubuntu14.1.

CVSS Base Scores

version 3.1