Activity log for bug #401503

Date Who What changed Old value New value Message
2009-07-19 21:34:43 Michael Gilbert bug added bug
2009-07-19 21:36:18 Michael Gilbert bug task added sysvinit (Debian)
2009-07-19 21:36:49 Michael Gilbert description hello, there is a method [1] that is described as a means to recover a forgotten password, but it also allows enables malicious local users to gain root access. this is very bad indeed. also see debian bug report [2], which hasn't seen much activity for quite some time. however, this is because the conditions for exploitation, in particular not setting a password for the rot account, are non-default on debian. these conditions are the default on ubuntu, which makes this so bad. this vulnerability has been present since at least dapper (and probably since warty); whichever version first introduced no-root. [1] http://linuxwave.blogspot.com/2008/09/ubuntu-forgotten-password.html [2] http://bugs.debian.org/517018 hello, there is a method [1] that is described as a means to recover a forgotten password, but it also enables malicious local users to gain root access. this is very bad indeed. also see debian bug report [2], which hasn't seen much activity for quite some time. however, this is because the conditions for exploitation, in particular not setting a password for the root account, are non-default on debian. these conditions are the default on ubuntu, which makes this so bad. this vulnerability has been present since at least dapper (and probably since warty); whichever version first introduced no-root. [1] http://linuxwave.blogspot.com/2008/09/ubuntu-forgotten-password.html [2] http://bugs.debian.org/517018
2009-07-20 10:51:06 Scott James Remnant (Canonical) visibility private public
2009-07-20 10:51:06 Scott James Remnant (Canonical) security vulnerability yes no
2009-07-20 10:57:15 Scott James Remnant (Canonical) upstart: status New Won't Fix
2010-05-10 22:29:30 Scott James Remnant (Canonical) removed subscriber Scott James Remnant