CVE-2006-1183
published 2006-03-13CVE-2006-1183: The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable…
PriorityP432high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
3.30%
87.7th percentile
The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable permissions, which allows local users to gain privileges.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | shadow | — | — |
| ubuntu | ubuntu_linux | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_debian7.2LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2006-1183: shadow - The Ubuntu 5.10 installer does not properly clear passwords from the installer l...
vendor_debian·2006·CVSS 7.2
CVE-2006-1183 [HIGH] CVE-2006-1183: shadow - The Ubuntu 5.10 installer does not properly clear passwords from the installer l...
The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable permissions, which allows local users to gain privileges.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-crpp-368c-254j: The Ubuntu 5
ghsa_unreviewed·2022-05-01
CVE-2006-1183 [HIGH] GHSA-crpp-368c-254j: The Ubuntu 5
The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable permissions, which allows local users to gain privileges.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/19200http://securitytracker.com/id?1015761http://www.osvdb.org/23868http://www.securityfocus.com/bid/17086http://www.vupen.com/english/advisories/2006/0927https://exchange.xforce.ibmcloud.com/vulnerabilities/25170https://launchpad.net/distros/ubuntu/+source/shadow/+bug/34606https://usn.ubuntu.com/262-1/http://secunia.com/advisories/19200http://securitytracker.com/id?1015761http://www.osvdb.org/23868http://www.securityfocus.com/bid/17086http://www.vupen.com/english/advisories/2006/0927https://exchange.xforce.ibmcloud.com/vulnerabilities/25170https://launchpad.net/distros/ubuntu/+source/shadow/+bug/34606https://usn.ubuntu.com/262-1/
2006-03-13
Published