1.9
CVSSv2

CVE-2006-6614

Published: 18/12/2006 Updated: 29/07/2017
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose file permissions allow it to be copied to other hosts when fai-savelog is called and allows malicious users to obtain the hash.

Vulnerable Product Search on Vulmon Subscribe to Product

thomas lange fully automated installation 2.1

thomas lange fully automated installation 3.1.2

debian debian linux 3.1