The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose file permissions allow it to be copied to other hosts when fai-savelog is called and allows attackers to obtain the hash.
2006-12-18T02:28:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 1.9 (LOW)
AV:L/AC:M/Au:N/C:P/I:N/A:N
3.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | thomas_lange | fully_automated_installation | 2.1 | Yes |
Application | thomas_lange | fully_automated_installation | 3.1.2 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |
Operating System | debian | debian_linux | 3.1 | Yes |