PT-2006-2200 · Canonical · Ubuntu

Karl Øie

+1

·

Published

2006-03-13

·

Updated

2018-10-03

·

CVE-2006-1183

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ubuntu version 5.10
Description The issue concerns the Ubuntu 5.10 installer, which fails to properly clear passwords from the installer log file, specifically questions.dat. This file is left with world-readable permissions, allowing local users to potentially gain privileges.
Recommendations For Ubuntu version 5.10, consider restricting access to the questions.dat log file to prevent unauthorized users from reading its contents. As a temporary workaround, manually remove or secure the questions.dat file after installation to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1183

Affected Products

Ubuntu