UBUNTU-CVE-2015-8370
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-8370
UBUNTU-CVE-2015-8370
Summary:
Details: Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grub_username_get function in grub-core/normal/auth.c or the (2) grub_password_get function in lib/crypto.c, which trigger an "Off-by-two" or "Out of bounds overwrite" memory error.
References: https://ubuntu.com/security/CVE-2015-8370, https://twitter.com/lostinsecurity/status/674925944524640257, http://hmarco.org/bugs/CVE-2015-8370-Grub2-authentication-bypass.html, https://ubuntu.com/security/notices/USN-2836-1, https://www.cve.org/CVERecord?id=CVE-2015-8370
Affected packages
Package
Name: grub2
Purl: pkg:deb/ubuntu/[email protected]~beta2-9ubuntu1.6?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
