[Git][security-tracker-team/security-tracker][master] Add CVE-2022-1804/accountsservice

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Mar 25 21:13:14 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1c36cd2f by Salvatore Bonaccorso at 2025-03-25T22:11:32+01:00
Add CVE-2022-1804/accountsservice

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -243384,7 +243384,8 @@ CVE-2022-31240
 CVE-2022-1805 (When connecting to Amazon Workspaces, the SHA256 presented by AWS conn ...)
 	NOT-FOR-US: Tera2
 CVE-2022-1804 (accountsservice no longer drops permissions when writting .pam_environ ...)
-	TODO: check
+	- accountsservice <not-affected> (Ubuntu-specific with dropped 0010-set-language.patch)
+	NOTE: https://bugs.launchpad.net/ubuntu/+source/accountsservice/+bug/1974250
 CVE-2022-1803 (Improper Restriction of Rendered UI Layers or Frames in GitHub reposit ...)
 	NOT-FOR-US: Trudesk
 CVE-2022-1802 (If an attacker was able to corrupt the methods of an Array object in J ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1c36cd2f35134e1677b0988ba419114fddd63bd3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1c36cd2f35134e1677b0988ba419114fddd63bd3
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250325/1d8bfd29/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list