Summary
Ubuntu Update for Linux kernel vulnerabilities USN-663-1
Solution
Please Install the Updated Packages.
Insight
It was discovered that passwords changed (or new users created) via the "
Users and Groups"
tool were created with 3DES hashing. This reduced the security of stored user passwords, and was a regression from the correct MD5 hashing. This update fixes the problem
future password changes
will correct the hashing used. We apologize for the inconvenience.
Affected
system-tools-backends regression on Ubuntu 8.10
Severity
Classification
-
CVE CVE-2008-6792 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
Related Vulnerabilities