CVE-2006-1844
EPSS 0.07%
Description
The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges.
How to fix CVE-2006-1844
To remediate CVE-2006-1844, upgrade the affected package to a fixed version below.
- Debian/shadow—upgrade to 1:4.0.14-9 or later
Is CVE-2006-1844 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1:4.0.14-9