CVE-2006-1183: High severity Ubuntu Ubuntu Linux vulnerability
The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable permissions, which allows local users to gain privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1183?
CVE-2006-1183 is considered a moderate severity vulnerability due to the potential for local privilege escalation.
How do I fix CVE-2006-1183?
To fix CVE-2006-1183, ensure that the installer log file permissions are corrected to restrict access to sensitive information.
Who is affected by CVE-2006-1183?
CVE-2006-1183 affects users of Ubuntu 5.10 who have installed the operating system and may have local access.
What access does CVE-2006-1183 allow to an attacker?
CVE-2006-1183 allows local users to access sensitive passwords stored in world-readable installer log files, potentially leading to privilege escalation.
Is CVE-2006-1183 still a concern today?
While CVE-2006-1183 is an old vulnerability, it is still a concern for any systems running the affected version of Ubuntu if not patched.