CVE-2006-6614

The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose file permissions allow it to be copied to other hosts when fai-savelog is called and allows attackers to obtain the hash.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:thomas_lange:fully_automated_installation:2.1:*:*:*:*:*:*:*
cpe:2.3:a:thomas_lange:fully_automated_installation:3.1.2:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:3.1:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:alpha:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:amd64:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:arm:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:hppa:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:ia-32:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:ia-64:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:m68k:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:mips:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:mipsel:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:ppc:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:s-390:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:3.1:*:sparc:*:*:*:*:*

History

21 Nov 2024, 00:23

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=402644 - Exploit () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=402644 - Exploit
References () http://secunia.com/advisories/23330 - Vendor Advisory () http://secunia.com/advisories/23330 - Vendor Advisory
References () http://www.securityfocus.com/bid/21579 - () http://www.securityfocus.com/bid/21579 -
References () http://www.vupen.com/english/advisories/2006/4995 - () http://www.vupen.com/english/advisories/2006/4995 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/30892 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/30892 -

Information

Published : 2006-12-18 02:28

Updated : 2024-11-21 00:23


NVD link : CVE-2006-6614

Mitre link : CVE-2006-6614

CVE.ORG link : CVE-2006-6614


JSON object : View

Products Affected

debian

  • debian_linux

thomas_lange

  • fully_automated_installation