Univention Bugzilla – Bug 40280
grub2: CVE-2015-8370 (4.1)
Last modified: 2016-10-05 12:46:41 CEST
The following issues have been identified in grub2: * buffer overflow when checking password entered during bootup (CVE-2015-8370) Fixed in wheezy version 1.99-27+deb7u3. Fixed in jessie version 2.02~beta2-22+deb8u1.
This is fixed via the import of a newer grub2 version in Bug #39009
Advisories: grub-efi-amd64-signed.yaml grub2.yaml
OK: # cat /etc/grub.d/01_password #!/bin/sh cat << EOF set superusers="root" password_pbkdf2 root grub.pbkdf2.sha512.10000.D6F136B5C861E1878554E008633AD8E8C1D433EF96B8CD936BD543D746E1208496573259A9B6A4C59088128C97763C1B97B03EBEC0279D169C4A184E832EDB6C.D2FC47B3CA92D131B28CE7BC071D07B7C17855EE487FED12DEAAD86973CAE87D03F3150BF2FEED094B626C864C7F51F37566E28C55F3304B3EECF782682B5282 EOF OK: upgrade OK: zless /usr/share/doc/grub2-common/changelog.Debian.gz OK: CVE-2015-8370 OK: grub2.yaml OK: grub-efi-amd64-signed.yaml OK-BUT-TBC: errata-announce -VVBB --only grub2.yaml OK-BUT-TBC: errata-announce -VVBB --only grub-efi-amd64-signed.yaml
<http://errata.software-univention.de/ucs/4.1/101.html> <http://errata.software-univention.de/ucs/4.1/102.html>