Return to CVE list

CVE-2006-1183

7.2
Critical

CVE-2006-1183

cve@mitre.org
Deferred

Description

The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable permissions, which allows local users to gain privileges.

Exploits

15792006-03-12localLinux

Ubuntu 5.10 Installer - Password Disclosure

By Kristian Hermansen