CVE-2006-1772: High severity Debian Debian Linux vulnerability
debconf in Debian GNU/Linux, when configuring mnogosearch in the mnogosearch-common 3.2.31-1 package, uses the world-readable config.dat file instead of the restricted passwords.dat for storing the cleartext database administrator password in the mnogosearch-common/databaseadminpass record, which allows local users to view the password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1772?
CVE-2006-1772 is classified as a medium severity vulnerability due to the exposure of sensitive information.
How do I fix CVE-2006-1772?
To fix CVE-2006-1772, you should update the mnogosearch-common package to a version that no longer uses world-readable files for sensitive configuration.
Which systems are affected by CVE-2006-1772?
CVE-2006-1772 affects Debian GNU/Linux version 3.1 across various architectures including mips, ia-64, and arm.
What type of vulnerability is CVE-2006-1772?
CVE-2006-1772 is an information disclosure vulnerability related to misconfigured file permissions.
What does CVE-2006-1772 expose?
CVE-2006-1772 exposes the cleartext database administrator password through a world-readable configuration file.