The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable permissions, which allows local users to gain privileges.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ubuntu_linux | Ubuntu | 5.10 (including) | 5.10 (including) |
Cdebconf | Ubuntu | dapper | * |
Cdebconf | Ubuntu | devel | * |
Cdebconf | Ubuntu | edgy | * |
Cdebconf | Ubuntu | feisty | * |