PT-2006-2835 · Debian · Base-Config+1
Joey Hess
·
Publicado
2006-04-19
·
Atualizado
2020-08-11
·
CVE-2006-1844
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Debian installer for shadow version 4.0.14
Debian installer for base-config version 2.53.10
Description
The issue concerns sensitive information being included in world-readable log files by the Debian installer. This information includes preseeded passwords and pppoeconf passwords, which could potentially allow local users to gain privileges.
Recommendations
For shadow version 4.0.14, restrict access to the log files generated by the Debian installer to prevent unauthorized users from reading sensitive information.
For base-config version 2.53.10, consider modifying the installer to exclude sensitive information from log files or apply appropriate permissions to limit access to these logs.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Debian
Base-Config