CVE-2006-3597

Published: 18 July 2006

passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank instead of locking it when the administrator selects the "Go Back" option after the final "Installation complete" message and uses the main menu, which causes the password to be zeroed out in the installer's memory.

Priority

Unknown

Status

Package Release Status
shadow
Launchpad, Ubuntu, Debian
Upstream Needs triage