Bug 41364 - grub2: CVE-2015-8370 (3.3)
grub2: CVE-2015-8370 (3.3)
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 3.3
Other Linux
: P4 normal (vote)
: UCS 3.3-0-errata
Assigned To: Janek Walkenhorst
Philipp Hahn
:
Depends on: 40282 41497
Blocks:
  Show dependency treegraph
 
Reported: 2016-05-26 21:07 CEST by Arvid Requate
Modified: 2016-09-21 21:27 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Security
Max CVSS v3 score:
requate: Patch_Available+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Arvid Requate univentionstaff 2016-05-26 21:07:29 CEST
Needs to be fixed in UCS 3.3 as well.


+++ This bug was initially created as a clone of Bug #40282 +++

The following issues have been identified in grub2:

* buffer overflow when checking password entered during bootup (CVE-2015-8370)

Fixed in squeeze version 1.98+20100804-14+squeeze2.
Comment 1 Janek Walkenhorst univentionstaff 2016-05-31 17:09:31 CEST
TODO: Set /var/univention/buildsystem2/config/versions/grub2 to 110 before build.
Comment 2 Janek Walkenhorst univentionstaff 2016-06-08 18:27:21 CEST
Package and patches copied to errata3.3-0 from errata3.2-8
Patches fixed for correct quilt-patch-patching.

Requires Bug #41497

Advisory: grub2.yaml
Tests (i386): OK
Comment 3 Philipp Hahn univentionstaff 2016-06-15 15:16:19 CEST
OK: aptitude install '?source-package(grub2)~i'
OK: printf 'set superusers="benutzer"\npassword benutzer univention\n' >> /etc/grub.d/40_custom && update-grub && reboot
OK: no crash

OK: zless /usr/share/doc/grub2-common/changelog.Debian.gz

OK: grub2.yaml
OK: errata-announce -V --only grub2.yaml
Comment 4 Janek Walkenhorst univentionstaff 2016-07-21 13:32:02 CEST
<http://errata.software-univention.de/ucs/3.3/10.html>