Bug 40280

Summary: grub2: CVE-2015-8370 (4.1)
Product: UCS Reporter: Arvid Requate <requate>
Component: Security updatesAssignee: Janek Walkenhorst <walkenhorst>
Status: CLOSED FIXED QA Contact: Philipp Hahn <hahn>
Severity: normal    
Priority: P4 CC: gohmann
Version: UCS 4.1Flags: requate: Patch_Available+
Target Milestone: UCS 4.1-0-errata   
Hardware: Other   
OS: Linux   
What kind of report is it?: Security Issue What type of bug is this?: ---
Who will be affected by this bug?: --- How will those affected feel about the bug?: ---
User Pain: Enterprise Customer affected?:
School Customer affected?: ISV affected?:
Waiting Support: Flags outvoted (downgraded) after PO Review:
Ticket number: Bug group (optional): Security
Max CVSS v3 score:

Description Arvid Requate univentionstaff 2015-12-17 14:34:32 CET
The following issues have been identified in grub2:

* buffer overflow when checking password entered during bootup (CVE-2015-8370)

Fixed in wheezy version 1.99-27+deb7u3.
Fixed in jessie version 2.02~beta2-22+deb8u1.
Comment 1 Janek Walkenhorst univentionstaff 2015-12-18 15:43:07 CET
This is fixed via the import of a newer grub2 version in Bug #39009
Comment 2 Janek Walkenhorst univentionstaff 2016-01-25 18:52:27 CET
Advisories: grub-efi-amd64-signed.yaml grub2.yaml
Comment 3 Philipp Hahn univentionstaff 2016-02-01 14:00:23 CET
OK: # cat /etc/grub.d/01_password 
#!/bin/sh
cat << EOF
set superusers="root"
password_pbkdf2 root grub.pbkdf2.sha512.10000.D6F136B5C861E1878554E008633AD8E8C1D433EF96B8CD936BD543D746E1208496573259A9B6A4C59088128C97763C1B97B03EBEC0279D169C4A184E832EDB6C.D2FC47B3CA92D131B28CE7BC071D07B7C17855EE487FED12DEAAD86973CAE87D03F3150BF2FEED094B626C864C7F51F37566E28C55F3304B3EECF782682B5282
EOF
OK: upgrade
OK: zless /usr/share/doc/grub2-common/changelog.Debian.gz
OK: CVE-2015-8370

OK: grub2.yaml
OK: grub-efi-amd64-signed.yaml
OK-BUT-TBC: errata-announce -VVBB --only grub2.yaml
OK-BUT-TBC: errata-announce -VVBB --only grub-efi-amd64-signed.yaml