You are here
Home > Preporuke > Sigurnosni propust programskog paketa grub2

Sigurnosni propust programskog paketa grub2

  • Detalji os-a: LUB
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-2836-1
December 15, 2015

grub2 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 15.10
– Ubuntu 15.04
– Ubuntu 14.04 LTS
– Ubuntu 12.04 LTS

Summary:

GRUB password protection can be bypassed.

Software Description:
– grub2: GRand Unified Bootloader

Details:

Hector Marco and Ismael Ripoll discovered that GRUB incorrectly handled
the backspace key when configured to use authentication. A local attacker
could use this issue to bypass GRUB password protection.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
grub2-common 2.02~beta2-29ubuntu0.2

Ubuntu 15.04:
grub2-common 2.02~beta2-22ubuntu1.4

Ubuntu 14.04 LTS:
grub2-common 2.02~beta2-9ubuntu1.6

Ubuntu 12.04 LTS:
grub2-common 1.99-21ubuntu3.19

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2836-1
CVE-2015-8370

Package Information:
https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-29ubuntu0.2
https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-22ubuntu1.4
https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6
https://launchpad.net/ubuntu/+source/grub2/1.99-21ubuntu3.19

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAEBCgAGBQJWcHEjAAoJEGVp2FWnRL6TnZsP/2Ke8EtOIYXPuSjq1JR+CAs+
7KQhc2WWMYjnKzF3kHzi782cV7mDX99XswcFJq1vs6txoGk1J2S+I8LeyccGKGBK
HOUNUBbvjIbjxX0wZubklfM2LLuX/6Zgn9lTIIym8PA4K8b17K99/NciQDrmVaa8
+jtPyA9GWYYUc3Fx11uSWeC8KprqbSsHi4tQBQgS4F4SbyFn8cC13+aserLyF3eS
h4VabcXB6tydT5FlAbd2nFXPCumvGkt7Q8fPScXISk9Z2jwmZ4yjer5ok0Zog8dH
Uy9viCJq0GHuUwUQJBX1WvaHIH6OTQj4AjcrGrA7ZXmIo2VNUV5PjqMQYU+8cALa
0u6d3spKfMK+KKo0m1jwY4tFfOx5/MlREnCvhM8rEJHKo4goBZ+3k2sWLHr/0Aur
vUq1auFvtfShANXZaqs202Cqwq1YNSD2Lyth3ddG7M11MRbkvL1UyIjabN+oz3rx
wqTeUtzlrgQNekN8K7QJfiEfJ/kuM5hK505c+Sqn1c6dhAxXFTXBD0YtDebNGQuy
jnyiUulfhNSkOLvrUKFY3EnTwH2kb95phd2YuKc3AM5IkHExDS9FOEajZFpFUkSo
gQnaw/w+X5G70rq8MgD7GDqmXve+Hocmem2I3s4Q09ZvgKNLdwIQ7pZ/S1gQBcAC
5Xc0d8fCEp5OvZeXyPwu
=hWmL
—–END PGP SIGNATURE—–

AutorTomislav Protega
Cert idNCERT-REF-2015-12-0001-ADV
CveCVE-2015-8370
ID izvornikaUSN-2836-1
Proizvodgrub2
Izvorhttp://www.ubuntu.com
Top
More in Preporuke
Sigurnosni nedostaci programskog paketa chromium-browser

Otkriveni su sigurnosni nedostaci u programskom paketu chromium-browser. Otkriveni nedostaci potencijalnim napadačima omogućuju izvođenje napada uskraćivanjem usluge i umetanje proizvoljnog...

Close