CVE-2006-3597

Publication date 18 July 2006

Last updated 24 July 2024


Ubuntu priority

passwd before 1:4.0.13 on Ubuntu 6.06 LTS leaves the root password blank instead of locking it when the administrator selects the "Go Back" option after the final "Installation complete" message and uses the main menu, which causes the password to be zeroed out in the installer's memory.

Status

Package Ubuntu Release Status
shadow 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Fixed 4.0.13-7ubuntu3.2