SUSE-SU-2015:2399-1
Dashboard / Vulnerabilities / SUSE-SU-2015:2399-1
SUSE-SU-2015:2399-1
Summary: Security update for grub2
Details: This update for grub2 provides the following fixes and enhancements: Security issue fixed: - Fix buffer overflows when reading username and password. (bsc#956631, CVE-2015-8370) Non security issues fixed: - Expand list of grub.cfg search path in PV Xen guests for systems installed on btrfs snapshots. (bsc#946148, bsc#952539) - Add --image switch to force zipl update to specific kernel. (bsc#928131) - Do not use shim lock protocol for reading PE header as it won't be available when secure boot is disabled. (bsc#943380) - Make firmware flaw condition be more precisely detected and add debug message for the case.
References: https://www.suse.com/support/update/announcement/2015/suse-su-20152399-1/, https://bugzilla.suse.com/928131, https://bugzilla.suse.com/943380, https://bugzilla.suse.com/946148, https://bugzilla.suse.com/952539, https://bugzilla.suse.com/956631, https://www.suse.com/security/cve/CVE-2015-8370
Affected packages
Package
Name: grub2
Purl: pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Desktop%2012
Affected ranges
Type: ECOSYSTEM
Events:
