PT-2006-4472 · Canonical · Ubuntu+1

Publicado

2006-07-14

·

Atualizado

2008-09-05

·

CVE-2006-3597

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions passwd version 1:4.0.13 and earlier on Ubuntu 6.06 LTS
Description The issue occurs when the administrator selects the "Go Back" option after the final "Installation complete" message and uses the main menu, causing the root password to be left blank instead of being locked. This happens because the password is zeroed out in the installer's memory.
Recommendations For passwd version 1:4.0.13 and earlier on Ubuntu 6.06 LTS, ensure that the "Go Back" option is not selected after the final "Installation complete" message to prevent the root password from being left blank. Alternatively, manually set a strong root password after installation to mitigate the risk.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3597

Produtos afetados

Ubuntu
Passwd