yocto ▾
›
master ▾
›
vulnerability
›
CVE-2023-3297
Component Overview
Vulnerability Overview
Name
CVE-2023-3297
Source
NVD (
link
)
Debian (
link
)
Description
In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
CWEs
CWE-416
CWE-416
Published Date
Sep 1, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2024182
Exploit
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3297
Third Party Advisory
https://securitylab.github.com/advisories/GHSL-2023-139_accountsservice/
Exploit
https://ubuntu.com/security/notices/USN-6190-1
Vendor Advisory
https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/2024182
Exploit
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3297
Third Party Advisory
https://securitylab.github.com/advisories/GHSL-2023-139_accountsservice/
Exploit
https://ubuntu.com/security/notices/USN-6190-1
Vendor Advisory
Analysis
#
Affected Component
Analysis
accountsservice
False Positive
Vulnerability Ratings
#
8.1
CVSSv31
7.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
accountsservice
yocto
kirkstone
22.08.8
Not Affected
accountsservice
yocto
scarthgap
22.08.8
False Positive