{"api_version":"1","generated_at":"2026-07-23T06:22:49+00:00","cve":"CVE-2006-3597","urls":{"html":"https://cve.report/CVE-2006-3597","api":"https://cve.report/api/cve/CVE-2006-3597.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-3597","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-3597"},"summary":{"title":"CVE-2006-3597","description":"passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank instead of locking it when the administrator selects the \"Go Back\" option after the final \"Installation complete\" message and uses the main menu, which causes the password to be zeroed out in the installer's memory.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-07-18 15:37:00","updated_at":"2008-09-05 21:07:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.osvdb.org/27091","name":"27091","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/21022","name":"21022","refsource":"SECUNIA","tags":["Patch","Vendor Advisory"],"title":"Ubuntu Installer Empty Root Password Security Issue - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-316-1","name":"USN-316-1","refsource":"UBUNTU","tags":["Exploit","Patch"],"title":"usn/usn-316-1 - Ubuntu: Linux for human beings","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-3597","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3597","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"3597","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ubuntu","cpe5":"ubuntu_linux","cpe6":"6.06_lts","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3597","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"ubuntu","cpe5":"ubuntu_linux","cpe6":"6.06_lts","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-3597","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank instead of locking it when the administrator selects the \"Go Back\" option after the final \"Installation complete\" message and uses the main menu, which causes the password to be zeroed out in the installer's memory."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"USN-316-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/usn-316-1"},{"name":"27091","refsource":"OSVDB","url":"http://www.osvdb.org/27091"},{"name":"21022","refsource":"SECUNIA","url":"http://secunia.com/advisories/21022"}]}},"nvd":{"publishedDate":"2006-07-18 15:37:00","lastModifiedDate":"2008-09-05 21:07:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:ubuntu:ubuntu_linux:6.06_lts:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"3597","Ordinal":"18923","Title":"CVE-2006-3597","CVE":"CVE-2006-3597","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"3597","Ordinal":"1","NoteData":"passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank instead of locking it when the administrator selects the \"Go Back\" option after the final \"Installation complete\" message and uses the main menu, which causes the password to be zeroed out in the installer's memory.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"3597","Ordinal":"2","NoteData":"2006-07-14","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"3597","Ordinal":"3","NoteData":"2006-07-26","Type":"Other","Title":"Modified"}]}}}