PT-2006-2835 · Debian · Base-Config+1

Joey Hess

·

Publicado

2006-04-19

·

Atualizado

2020-08-11

·

CVE-2006-1844

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Debian installer for shadow version 4.0.14 Debian installer for base-config version 2.53.10
Description The issue concerns sensitive information being included in world-readable log files by the Debian installer. This information includes preseeded passwords and pppoeconf passwords, which could potentially allow local users to gain privileges.
Recommendations For shadow version 4.0.14, restrict access to the log files generated by the Debian installer to prevent unauthorized users from reading sensitive information. For base-config version 2.53.10, consider modifying the installer to exclude sensitive information from log files or apply appropriate permissions to limit access to these logs.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1844

Produtos afetados

Debian
Base-Config