CVE-2006-3597
Summary
| CVE | CVE-2006-3597 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-07-18 15:37:00 UTC |
| Updated | 2008-09-05 21:07:00 UTC |
| Description | passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank instead of locking it when the administrator selects the "Go Back" option after the final "Installation complete" message and uses the main menu, which causes the password to be zeroed out in the installer's memory. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Ubuntu | Ubuntu Linux | 6.06_lts | All | All | All |
| Operating System | Ubuntu | Ubuntu Linux | 6.06_lts | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 27091 | OSVDB | www.osvdb.org | |
| Ubuntu Installer Empty Root Password Security Issue - Advisories - Secunia | SECUNIA | secunia.com | Patch, Vendor Advisory |
| usn/usn-316-1 - Ubuntu: Linux for human beings | UBUNTU | www.ubuntu.com | Exploit, Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.