CVE-2015-8370
Publication date 11 December 2015
Last updated 24 July 2024
Ubuntu priority
Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grub_username_get function in grub-core/normal/auth.c or the (2) grub_password_get function in lib/crypto.c, which trigger an "Off-by-two" or "Out of bounds overwrite" memory error.
Status
Package | Ubuntu Release | Status |
---|---|---|
grub2 | ||
14.04 LTS trusty |
Fixed 2.02~beta2-9ubuntu1.6
|
|
Patch details
Package | Patch details |
---|---|
grub2 |
References
Related Ubuntu Security Notices (USN)
- USN-2836-1
- GRUB vulnerability
- 15 December 2015