First published: Wed Apr 19 2006(Updated: )
The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Base-config | =2.53.10 | |
Shadow-utils | =4.0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1844 is considered a medium severity vulnerability due to the exposure of sensitive information in world-readable log files.
To mitigate CVE-2006-1844, ensure that sensitive log files are not world-readable and restrict access to them appropriately.
CVE-2006-1844 affects the Debian packages shadow version 4.0.14 and base-config version 2.53.10.
CVE-2006-1844 exposes sensitive information such as preseeded passwords and pppoeconf passwords in log files.
Yes, local users can potentially exploit CVE-2006-1844 to gain unauthorized privileges due to the exposed sensitive information.