CVE Vulnerabilities

CVE-2008-5103

Published: Nov 17, 2008 | Modified: Aug 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
HIGH

The (1) python-vm-builder and (2) ubuntu-vm-builder implementations in VMBuilder 0.9 in Ubuntu 8.10 omit the -e option when invoking chpasswd with a root:! argument, which configures the root account with a cleartext password of ! (exclamation point) and allows attackers to bypass intended login restrictions.

Affected Software

Name Vendor Start Version End Version
Vmbuilder Dcgrendel 0.9 (including) 0.9 (including)
Vm-builder Ubuntu devel *
Vm-builder Ubuntu intrepid *

References