Ubuntu security advisory
SecurityFocus reports a vulnerability in Ubuntu The problem is that the root password is stored in clear-text in a world-readable installer log file, verifiable by running grep password /var/log/installer/cdebconf/questions.dat...