Quote:
|
Originally Posted by tuxrunner
|
While yes, this is a major security bug, telling people to update their packages will NOT fix the problem. Simply check the reported files manually or by using grep for your password. If there then either edit the files and remove the password or delete the files entirely. These files are not required system files and will not hurt anything with their removal.
I'd also HIGHLY suggest that you change at very least your root password and better yet all system passwords.
The 2 files the password has been found in ClearText in include:
/var/log/installer/cdebconf/questions.dat
/var/log/debian-installer/cdebconf/questions.dat
Note that this is NOT a bug found on Debian Linux systems but HAS been found on both Ubuntu and KUbuntu systems.
UPDATE EDIT: My mistake folks as an update will now fix this as Colin Watson (the Ubuntu installer maintainer) was able to upload a fix for this last night. Still, its a good thing to double check your files AND remember to still change your password!
This only affects 5.10 Breezy Badger users and those who have done an upgrade from an existing 5.10 system.