The (1) python-vm-builder and (2) ubuntu-vm-builder implementations in VMBuilder 0.9 in Ubuntu 8.10 omit the -e option when invoking chpasswd with a root:! argument, which configures the root account with a cleartext password of ! (exclamation point) and allows attackers to bypass intended login restrictions.
2008-11-17T18:18:48.017
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | dcgrendel | vmbuilder | 0.9 | Yes |
Operating System | ubuntu | ubuntu_linux | 6.06 | No |
Operating System | ubuntu | ubuntu_linux | 7.10 | No |
Operating System | ubuntu | ubuntu_linux | 8.04 | No |
Operating System | ubuntu | ubuntu_linux | 8.10 | No |