Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Microsoft Office Clone Updates Interface, Improves File Support
· Windows Firewall Control 4.0.0.0 released
· 10 amazing Linux desktop environments you've probably never seen
· Microsoft Office security flaw hits thousands in latest hacker attack
· Kubuntu 13.04 Raring Ringtail Review
· Windows Mobile 7 concept video shows why Microsoft dumped the platform
· Building a Thin Mini-ITX PC and more
· Microsoft wants consumers to control the camera by voice, according to filed patent
· Dell replays Windows 8 blame card as PC sales slide
· m23 rock 13.1 released

Upcoming News
· Seidio Active Case Combo for HTC One Review @ TestFreaks
· Jawbone UP Wristband
· Seagate Desktop HDD.15 4TB Hard Drive Review @ Hardware Canucks
· Steelseries WoW MMO Gaming Mouse Legendary Edition Review
· Luxa2 P1 7000mAh High Capacity Battery & Charger Review @ OCC
· GUNNAR Intercept Gaming Eyewear Video Review with Kaeyi Dream @ HardwareHeaven.com
· [slackware-security] kernel (SSA:2013-140-01)
· [CentOS-announce] CEBA-2013:0835 CentOS 6 selinux-policy Update
· Ubuntu Weekly Newsletter Issue 317
· [RHSA-2013:0841-01] Important: kernel security update

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6393 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 658 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4517 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 723 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1114 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » March 2006 » USN-262-1: Ubuntu 5.10 installer password disclosure

USN-262-1: Ubuntu 5.10 installer password disclosure

Posted by Bob on: 03/13/2006 01:52 AM [ Print | 0 comment(s) ]

A new Ubuntu 5.10 installer password disclosure update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-262-1 March 12, 2006
Ubuntu 5.10 installer vulnerability
https://launchpad.net/bugs/34606
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D

A security issue affects the following Ubuntu releases:

Ubuntu 5.10 (Breezy Badger)

The following packages are affected:

base-config
passwd

The problem can be corrected by upgrading the affected package to
version 2.67ubuntu20 (base-config) and 1:4.0.3-37ubuntu8 (passwd). In
general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

Karl =D8ie discovered that the Ubuntu 5.10 installer failed to clean
passwords in the installer log files. Since these files were
world-readable, any local user could see the password of the first
user account, which has full sudo privileges by default.

The updated packages remove the passwords and additionally make the
log files readable only by root.

This does not affect the Ubuntu 4.10, 5.04, or the upcoming 6.04
installer. However, if you upgraded from Ubuntu 5.10 to the current
development version of Ubuntu 6.04 ('Dapper Drake'), please ensure
that you upgrade the passwd package to version 1:4.0.13-7ubuntu2 to
fix the installer log files.


Source archives:

http://security.ubuntu.com/ubuntu/pool/main/b/base-config/base-config_2=
=2E67ubuntu20.dsc
Size/MD5: 758 c22bb6e3be4d59aa93e84327f60e89ab
http://security.ubuntu.com/ubuntu/pool/main/b/base-config/base-config_2=
=2E67ubuntu20.tar.gz
Size/MD5: 577194 99eabbe70227169feaff28ff9062d097
http://security.ubuntu.com/ubuntu/pool/main/s/shadow/shadow_4.0.3-37ubu=
ntu8.diff.gz
Size/MD5: 1067297 9db7bb924125a5587380efc08f6787e1
http://security.ubuntu.com/ubuntu/pool/main/s/shadow/shadow_4.0.3-37ubu=
ntu8.dsc
Size/MD5: 876 50cdfae3bfbe1bb1bb4be192d7de19a7
http://security.ubuntu.com/ubuntu/pool/main/s/shadow/shadow_4.0.3.orig.=
tar.gz
Size/MD5: 1045704 b52dfb2e5e8d9a4a2aae0ca1b266c513

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/b/base-config/apt-setup-ude=
b_2.67ubuntu20_all.udeb
Size/MD5: 3298 dd42b2901f6f5d7525083c27cbb23407
http://security.ubuntu.com/ubuntu/pool/main/b/base-config/base-config_2=
=2E67ubuntu20_all.deb
Size/MD5: 291224 e95d7a1d25074ea57d444e817cef1850
http://security.ubuntu.com/ubuntu/pool/main/s/shadow/initial-passwd-ude=
b_4.0.3-37ubuntu8_all.udeb
Size/MD5: 1740 6c7bc8e12968d9876b6e1b27f0476484
http://security.ubuntu.com/ubuntu/pool/main/b/base-config/tzsetup-udeb_=
2.67ubuntu20_all.udeb
Size/MD5: 2760 f6ebc84fd2bff0275b1e64d53fdc9955

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/main/s/shadow/login_4.0.3-37ubun=
tu8_amd64.deb
Size/MD5: 180662 de75ded6034f0d7226dfbf0ec66e2be7
http://security.ubuntu.com/ubuntu/pool/main/s/shadow/passwd_4.0.3-37ubu=
ntu8_amd64.deb
Size/MD5: 589790 f90c48af4e1c55202f22127e72dbf45d

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/main/s/shadow/login_4.0.3-37ubun=
tu8_i386.deb
Size/MD5: 171882 347fa929d15c3689bd68fc487cc116c6
http://security.ubuntu.com/ubuntu/pool/main/s/shadow/passwd_4.0.3-37ubu=
ntu8_i386.deb
Size/MD5: 515580 b8c965e4a5c40d1c50e8816aeef689bc

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/main/s/shadow/login_4.0.3-37ubun=
tu8_powerpc.deb
Size/MD5: 179886 42ebfcd496b621bdab29e9a6b3f50522
http://security.ubuntu.com/ubuntu/pool/main/s/shadow/passwd_4.0.3-37ubu=
ntu8_powerpc.deb
Size/MD5: 568426 089edb3f8110ab191bba6d061b199385

--IU5/I01NYhRvwH70
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.1 (GNU/Linux)

iD8DBQFEFL1HDecnbV4Fd/IRAow2AKDbRm+b3Ag+lqJdrr3Mn1Gwhe1z6ACggJtY
JBjBqkZ2CvfJw8HBK1QQpRE=
=v72h
-----END PGP SIGNATURE-----


Bookmark and Share

« GLSA 200603-10 Cube: Multiple vulnerabilities · DSA 994-1: New freeciv packages fix denial of service »

Linux Compatible » News » March 2006 » USN-262-1: Ubuntu 5.10 installer password disclosure
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition