D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] [K]Ubuntu security hole

 

Just a little something to add. This only applies to users who
initialy installed version 5.10 Breezy Badger. Those who used 4.10
Warty or 5.04 Hoary as their base installation are, as far as I know,
unaffected.

On 3/13/06, David Johnson <dj@xxxxxxxxxxxxxxx> wrote:
> Hi all,
>
> Just a quick note to tell [K]Ubuntu users to apt-get upgrade.
>
> It seems that the Breezy installer leaves a world-readable file on the disk
> containing the plain-text password of your first user (which has sudo and
> therefore root privileges).
>
> https://launchpad.net/distros/ubuntu/+source/shadow/+bug/34606
>
> A fix is available (it was released just 12 hours after discovery - beat that
> proprietary software companies), just upgrade. Or you could just delete the
> offending files, as listed in the bug report linked above.
>
> Regards,
> David.
>
> --
> David Johnson
> www.david-web.co.uk - My Personal Website
> www.ethereye.org.uk - EtherEye Network Host Checker
> www.penguincomputing.co.uk - Need a Web Developer?
>
> --
> The Mailing List for the Devon & Cornwall LUG
> Mail majordomo@xxxxxxxxxxxxx with "unsubscribe list" in the
> message body to unsubscribe. FAQ: www.dcglug.org.uk/linux_adm/list-faq.html
>


--
Michael Dodd

--
The Mailing List for the Devon & Cornwall LUG
Mail majordomo@xxxxxxxxxxxxx with "unsubscribe list" in the
message body to unsubscribe. FAQ: www.dcglug.org.uk/linux_adm/list-faq.html