// For flags

CVE-2008-5103

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The (1) python-vm-builder and (2) ubuntu-vm-builder implementations in VMBuilder 0.9 in Ubuntu 8.10 omit the -e option when invoking chpasswd with a root:! argument, which configures the root account with a cleartext password of ! (exclamation point) and allows attackers to bypass intended login restrictions.

Las implementaciones (1) python-vm-builder y (2) ubuntu-vm-builder en VMBuilder v0.9 en Ubuntu v8.10 omiten la opción -e cuando invocan chpasswd con un argumento root:!, lo cual configura la cuenta raíz con una contraseña en texto claro de ! (punto de exclamación) y permite a atacantes evitar restricciones de login intencionadas.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-11-17 CVE Reserved
  • 2008-11-17 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-255: Credentials Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dcgrendel
Search vendor "Dcgrendel"
Vmbuilder
Search vendor "Dcgrendel" for product "Vmbuilder"
0.9
Search vendor "Dcgrendel" for product "Vmbuilder" and version "0.9"
-
Affected
in Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
6.06
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "6.06"
_nil_, lts
Safe
Dcgrendel
Search vendor "Dcgrendel"
Vmbuilder
Search vendor "Dcgrendel" for product "Vmbuilder"
0.9
Search vendor "Dcgrendel" for product "Vmbuilder" and version "0.9"
-
Affected
in Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
7.10
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "7.10"
-
Safe
Dcgrendel
Search vendor "Dcgrendel"
Vmbuilder
Search vendor "Dcgrendel" for product "Vmbuilder"
0.9
Search vendor "Dcgrendel" for product "Vmbuilder" and version "0.9"
-
Affected
in Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
8.04
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "8.04"
_nil_, lts
Safe
Dcgrendel
Search vendor "Dcgrendel"
Vmbuilder
Search vendor "Dcgrendel" for product "Vmbuilder"
0.9
Search vendor "Dcgrendel" for product "Vmbuilder" and version "0.9"
-
Affected
in Ubuntu
Search vendor "Ubuntu"
Ubuntu Linux
Search vendor "Ubuntu" for product "Ubuntu Linux"
8.10
Search vendor "Ubuntu" for product "Ubuntu Linux" and version "8.10"
-
Safe