---
title: "CVE-2006-3597\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2006-3597?format=md
keywords: index, follow
---

# CVE-2006-3597

Publication date 18 July 2006

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank
instead of locking it when the administrator selects the "Go Back" option
after the final "Installation complete" message and uses the main menu,
which causes the password to be zeroed out in the installer's memory.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| shadow | 7.04 feisty | Not affected |
| 6.10 edgy | Not affected |
| 6.06 LTS dapper | Fixed 4.0.13-7ubuntu3.2 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3597)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2006-3597)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2006-3597)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2006-3597)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2006-3597>
