Upstream information
Description
The user_change_icon_file_authorized_cb function in /usr/libexec/accounts-daemon in AccountsService before 0.6.22 does not properly check the UID when copying an icon file to the system cache directory, which allows local users to read arbitrary files via a race condition.NVD CVSS v2 Base Score: 1.9 (AV:L/AC:M/Au:N/C:P/I:N/A:N)
Novell/SUSE information
Novell Bugzilla entry: 768807 SUSE Security Advisories:- openSUSE-SU-2012:0845-1, published Fri, 6 Jul 2012 10:08:29 +0200 (CEST)
