Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
'Root' Password Readable in Clear Text on Ubuntu Breezy
#1

for all you ubuntu users out there, please read the following and act accordingly

 

from:- [/url]http://www.osnews.com/story.php?news_id=13951

 

[url=https://launchpad.net/distros/ubuntu/+bug/34606]https://launchpad.net/distros/ubuntu/+bug/34606

 

Quote:A major, critical bug and possible security threat has been discovered in Ubuntu Breezy. Apparantly, the 'root' password (not actually the root password because Ubuntu uses sudo) gets written into the installer's log files in clear text, and can be read by any account on the Ubuntu machine. The bug was first discovered and reproduced on the Ubuntu forums. The bug does not seem to affect Dapper, however, users upgrading from Breezy to Dapper might still be at risk because the log files are not modified.
 

cheers

anyweb

Reply
#2

Quick and easy solution is to remove both files:



Code:
rm /var/log/installer/cdebconf/questions.dat
rm /var/log/debian-installer/cdebconf/questions.dat




 

.. nasty when files like that are left just around :)

Reply
#3
Is this fixed? Is there any update that fix this problem?
Reply
#4

Hi guys,

 

I used this site to sort out the root password problem i had with ubuntu

 

http://www.fixya.com/support/t879022-ubunt...e_root_password

 

It's really clear and easy

 

Ubuntu ROCKS!!!!

Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)