Back to search
CVE-2015-8370
Published: Dec 16, 2015
Modified: Oct 21, 2024
PUBLISHED
Description
Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grub_username_get function in grub-core/normal/auth.c or the (2) grub_password_get function in lib/crypto.c, which trigger an "Off-by-two" or "Out of bounds overwrite" memory error.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
openSUSE-SU-2015:2392
vendor-advisory
openSUSE-SU-2016:0036
vendor-advisory
79358
vdb-entry
openSUSE-SU-2015:2375
vendor-advisory
1034422
vdb-entry
SUSE-SU-2015:2387
vendor-advisory
SUSE-SU-2015:2386
vendor-advisory
SUSE-SU-2015:2385
vendor-advisory
GLSA-201512-03
vendor-advisory
FEDORA-2015-cebe5133e7
vendor-advisory
USN-2836-1
vendor-advisory
FEDORA-2015-90c27b6e91
vendor-advisory
RHSA-2015:2623
vendor-advisory
SUSE-SU-2015:2399
vendor-advisory
DSA-3421
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now