Security Flaw in Actualizer Affects Debian OS Build Process
CVE-2025-47276

7.5HIGH

Key Information:

Vendor

Chewkeanho

Vendor
CVE Published:
13 May 2025

What is CVE-2025-47276?

Actualizer, a tool for creating Debian operating systems, has a vulnerability due to its reliance on OpenSSL's '-passwd' function, which employs SHA512 for password hashing. This method is less secure compared to more modern algorithms such as Yescript and Argon2i, leaving users at risk during OS deployments. To mitigate this risk, users must manually update the passwords for both the root and Alpha accounts post-deployment, optionally utilizing the new hashing capabilities offered in version 1.2.0. It's recommended that all Actualizer users upgrade to this version to ensure more secure password management.

Affected Version(s)

Actualizer < 1.2.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.