Re: [tlug] Fwd: Re: [linuxNUS] Possible HUGE Security Flaw inUbuntu Breezy (and maybe other versions)

On 3/14/06, Goh Lu Feng <> wrote:
I aplogise if this is old news... but I guess no  harm
hearing it again if u've already done so.

I hadn't heard, so thanks!
> Karl Řie discovered that the Ubuntu 5.10 installer
> failed to clean
> passwords in the installer log files. Since these
> files were
> world-readable, any local user could see the
> password
> of the first
> user account, which has full sudo privileges by
> default.

Ouch!  That one password system doesn't seem so good now....


