Bug 40280 - grub2: CVE-2015-8370 (4.1)
grub2: CVE-2015-8370 (4.1)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.1
Other Linux
: P4 normal (vote)
: UCS 4.1-0-errata
Assigned To: Janek Walkenhorst
Philipp Hahn
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2015-12-17 14:34 CET by Arvid Requate
Modified: 2016-10-05 12:46 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Ticket number:
Bug group (optional): Security
Max CVSS v3 score:
requate: Patch_Available+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2015-12-17 14:34:32 CET
The following issues have been identified in grub2:

* buffer overflow when checking password entered during bootup (CVE-2015-8370)

Fixed in wheezy version 1.99-27+deb7u3.
Fixed in jessie version 2.02~beta2-22+deb8u1.
Comment 1 Janek Walkenhorst univentionstaff 2015-12-18 15:43:07 CET
This is fixed via the import of a newer grub2 version in Bug #39009
Comment 2 Janek Walkenhorst univentionstaff 2016-01-25 18:52:27 CET
Advisories: grub-efi-amd64-signed.yaml grub2.yaml
Comment 3 Philipp Hahn univentionstaff 2016-02-01 14:00:23 CET
OK: # cat /etc/grub.d/01_password 
#!/bin/sh
cat << EOF
set superusers="root"
password_pbkdf2 root grub.pbkdf2.sha512.10000.D6F136B5C861E1878554E008633AD8E8C1D433EF96B8CD936BD543D746E1208496573259A9B6A4C59088128C97763C1B97B03EBEC0279D169C4A184E832EDB6C.D2FC47B3CA92D131B28CE7BC071D07B7C17855EE487FED12DEAAD86973CAE87D03F3150BF2FEED094B626C864C7F51F37566E28C55F3304B3EECF782682B5282
EOF
OK: upgrade
OK: zless /usr/share/doc/grub2-common/changelog.Debian.gz
OK: CVE-2015-8370

OK: grub2.yaml
OK: grub-efi-amd64-signed.yaml
OK-BUT-TBC: errata-announce -VVBB --only grub2.yaml
OK-BUT-TBC: errata-announce -VVBB --only grub-efi-amd64-signed.yaml