Univention Bugzilla – Bug 41364
grub2: CVE-2015-8370 (3.3)
Last modified: 2016-09-21 21:27:25 CEST
Needs to be fixed in UCS 3.3 as well. +++ This bug was initially created as a clone of Bug #40282 +++ The following issues have been identified in grub2: * buffer overflow when checking password entered during bootup (CVE-2015-8370) Fixed in squeeze version 1.98+20100804-14+squeeze2.
TODO: Set /var/univention/buildsystem2/config/versions/grub2 to 110 before build.
Package and patches copied to errata3.3-0 from errata3.2-8 Patches fixed for correct quilt-patch-patching. Requires Bug #41497 Advisory: grub2.yaml Tests (i386): OK
OK: aptitude install '?source-package(grub2)~i' OK: printf 'set superusers="benutzer"\npassword benutzer univention\n' >> /etc/grub.d/40_custom && update-grub && reboot OK: no crash OK: zless /usr/share/doc/grub2-common/changelog.Debian.gz OK: grub2.yaml OK: errata-announce -V --only grub2.yaml
<http://errata.software-univention.de/ucs/3.3/10.html>