1. Hey Guest Did you know you can win an Honor 10 phone worth ₹33,000 and an additional ₹70,000 in paytm vouchers, just by replying to some threads and taking part in the discussions happening in the Honor Hub?

    What are you waiting for? Start commenting and start winning! Remember to read the instructions posted here.

    Dismiss Notice

[Attention!!] Ubuntu users.. critical security notice!!

Discussion in 'Open Source' started by Satissh S, Mar 21, 2006.

Thread Status:
Not open for further replies.
  1. Satissh S

    Satissh S New Member

    Joined:
    Mar 23, 2005
    Messages:
    692
    Likes Received:
    2
    Trophy Points:
    0
    Location:
    Chennai , India
    No this aint that Ubuntu bug no 1 joke.. :p

    Thanks to gnurag for the info, there seems to be a CRITICAL bug in the ubuntu installer of 5.10 breezy related to passwd and sudo..
    According to the,
    Ubuntu Security Notice USN-262-1 March 12, 2006
    Source: http://www.ubuntu.com/usn/usn-262-1

    So update passwd package to version 1:4.0.13-7ubuntu2 if u havent already.. :|
     
  2. GNUrag

    GNUrag FooBar Guy

    Joined:
    Jun 22, 2004
    Messages:
    1,246
    Likes Received:
    5
    Trophy Points:
    0
    Location:
    Interwebs
    Also, delete this file:
    /var/log/installer/cdebconf/questions.dat
    from your system as it contains first user's password in plain text, and considering the fact that this file is world readable and first user has full sudo access... this is a security risk for public computers.

    mere
    $ grep "passwd/user-password" /var/log/installer/cdebconf/questions.dat
    gives up the password.
     
  3. praka123

    praka123 left this forum longback

    Joined:
    Sep 7, 2005
    Messages:
    7,513
    Likes Received:
    24
    Trophy Points:
    0
    Location:
    -
    this info is one week old :roll:
     
  4. GNUrag

    GNUrag FooBar Guy

    Joined:
    Jun 22, 2004
    Messages:
    1,246
    Likes Received:
    5
    Trophy Points:
    0
    Location:
    Interwebs
    10 days to be exact.
     
Thread Status:
Not open for further replies.

Share This Page