USN-663-1: system-tools-backends regression

Ubuntu Security Notice USN-663-1

5th November, 2008

system-tools-backends regression

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 8.10

Software description

  • system-tools-backends

Details

It was discovered that passwords changed (or new users created) via the
"Users and Groups" tool were created with 3DES hashing. This reduced the
security of stored user passwords, and was a regression from the correct
MD5 hashing. This update fixes the problem; future password changes
will correct the hashing used. We apologize for the inconvenience.

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 8.10:
system-tools-backends 2.6.0-1ubuntu1.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system upgrade is sufficient to effect the
necessary changes.

References

LP: 287134