First published: Mon Nov 17 2008(Updated: )
The (1) python-vm-builder and (2) ubuntu-vm-builder implementations in VMBuilder 0.9 in Ubuntu 8.10 omit the -e option when invoking chpasswd with a root:! argument, which configures the root account with a cleartext password of ! (exclamation point) and allows attackers to bypass intended login restrictions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dcgrendel Vmbuilder | =0.9 | |
Ubuntu Ubuntu Linux | =6.06-_nil_ | |
Ubuntu Ubuntu Linux | =7.10 | |
Ubuntu Ubuntu Linux | =8.04-_nil_ | |
Ubuntu Ubuntu Linux | =8.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.