CVE-2006-1844: Low severity debian base-config vulnerability
The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1844?
CVE-2006-1844 is considered a medium severity vulnerability due to the exposure of sensitive information in world-readable log files.
How do I fix CVE-2006-1844?
To mitigate CVE-2006-1844, ensure that sensitive log files are not world-readable and restrict access to them appropriately.
Which Debian packages are affected by CVE-2006-1844?
CVE-2006-1844 affects the Debian packages shadow version 4.0.14 and base-config version 2.53.10.
What information is exposed through CVE-2006-1844?
CVE-2006-1844 exposes sensitive information such as preseeded passwords and pppoeconf passwords in log files.
Can local users exploit CVE-2006-1844 for privilege escalation?
Yes, local users can potentially exploit CVE-2006-1844 to gain unauthorized privileges due to the exposed sensitive information.