security issues



"Karl Øie discovered that the Ubuntu 5.10 installer failed to clean
passwords in the installer log files. Since these files were
world-readable, any local user could see the password of the first
user account, which has full sudo privileges by default.

The updated packages remove the passwords and additionally make the
log files readable only by root."


Why on God's green earth was the password ever written to a file in
the first place?!?!?? I use ubuntu because it's "easy," not expecting
it to be ultra secure, but this is ridiculous. To compound the
problem the explanation given is awful... "since these files were
world-readable" should have been, "some dumbass wrote code that wrote
clear text passwords to disk"--the readability of the files is
irrelevant. I'm switching distros ASAP, there's no way I can trust
ubuntu after this.

--
lampajoo@xxxxxxxxx

--
ubuntu-users mailing list
ubuntu-users@xxxxxxxxxxxxxxxx
https://lists.ubuntu.com/mailman/listinfo/ubuntu-users



Relevant Pages

  • Re: ubuntu-users Digest, Vol 19, Issue 142
    ... passwords in the installer log files. ... any local user could see the password of the first ... The updated packages remove the passwords and additionally make the ... then a bug was posted. ...
    (Ubuntu)
  • Re: security issues
    ... passwords in the installer log files. ... any local user could see the password of the first ... The updated packages remove the passwords and additionally make the ... then a bug was posted. ...
    (Ubuntu)
  • Re: Dapper Drake verdict: It sucks
    ... I had to use the Ubuntu's packages, ... I really don't want to move this machine over to Debian as most ... all be my fault as I need to adjust sudo passwords or something ... Also reading the blogs about Debian developers, and Ubuntu seems to ...
    (Debian-User)
  • Re: security issues
    ... passwords in the installer log files. ... any local user could see the password of the first ... The updated packages remove the passwords and additionally make the ... I use ubuntu because it's "easy," not expecting ...
    (Ubuntu)
  • Re: trojan problem
    ... > assume an attack via ssh and a brute force hack, ... Under XP (not yet under Ubuntu because I don't know the tools yet) I'd ... passwords in a single AES-protected file that is in removable storage ... Getting infected by an open ssh, ...
    (Ubuntu)