Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2006-1844

Опубликовано: 19 апр. 2006
Источник: debian

Описание

The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
shadowfixed1:4.0.3-31sarge8sargepackage
base-confignot-affectedsargepackage
shadowfixed1:4.0.14-9package
base-configfixed2.68package

Примечания

  • The installer is fixed separately, but the postinst of the shadow update

  • corrects permissions of a faulty install

  • seems to be a duplicate of CVE-2006-1376

Связанные уязвимости

nvd
больше 19 лет назад

The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges.

github
больше 3 лет назад

The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges.