CVE-2012-2737: Ray Stode Accountsservice

Low severity, CVSS 1.9. EPSS: 0.4% chance of exploitation in the next 30 days.

The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.

Affected products

  • Ray Stode Accountsservice: up to and including 0.6.21; version 0.4 only; version 0.5 only; version 0.6 only; version 0.6.1 only; version 0.6.2 only; …

Published 2012-07-22. Last modified 2026-06-16.