CVE Vulnerabilities

CVE-2013-2069

Published: May 29, 2013 | Modified: Dec 06, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Red Hat livecd-tools before 13.4.4, 17.x before 17.17, 18.x before 18.16, and 19.x before 19.3, when a rootpw directive is not set in a Kickstart file, sets the root user password to empty, which allows local users to gain privileges.

Affected Software

Name Vendor Start Version End Version
Livecd-tools Redhat * 13.4.4 (excluding)
Livecd-tools Redhat 17.0 (including) 17.17 (excluding)
Livecd-tools Redhat 18.0 (including) 18.16 (excluding)
Livecd-tools Redhat 19.0 (including) 19.3 (excluding)

References