Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-5103

Overview

Vulnerability Score 7.2 7.2
CVE Id CVE-2008-5103
Last Modified 30 Oct 2012 11:06:49
Published 17 Nov 2008 01:18:48
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2008-5103

Summary

The (1) python-vm-builder and (2) ubuntu-vm-builder implementations in VMBuilder 0.9 in Ubuntu 8.10 omit the -e option when invoking chpasswd with a root:! argument, which configures the root account with a cleartext password of ! (exclamation point) and allows attackers to bypass intended login restrictions.

Vulnerable Systems

Application

  • Dcgrendel Vmbuilder 0.9


References

BID - 32292

SECUNIA - 32697

CONFIRM - https://bugs.launchpad.net/ubuntu/+source/vm-builder/+bug/296841

XF - vmbuilder-password-weak-security(46603)

UBUNTU - USN-670-1

CONFIRM - http://launchpadlibrarian.net/19619929/vm-builder_0.9-0ubuntu3.1.debdiff

OSVDB - 49996


Last Updated: 27 May 2016 10:49:47