Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5281

Опубликовано: 17 нояб. 2015
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.

It was discovered that grub2 builds for EFI systems contained modules that were not suitable to be loaded in a Secure Boot environment. An attacker could use this flaw to circumvent the Secure Boot mechanisms and load non-verified code. Attacks could use the boot menu if no password was set, or the grub2 configuration file if the attacker has root privileges on the system.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1264103grub2: modules built in on EFI builds that allow loading arbitrary code, circumventing secure boot

EPSS

Процентиль: 19%
0.0006
Низкий

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
почти 10 лет назад

The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.

nvd
почти 10 лет назад

The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.

debian
почти 10 лет назад

The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) ...

github
больше 3 лет назад

The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the configuration file or physically proximate attackers to bypass intended Secure Boot restrictions and execute non-verified code via the (3) boot menu.

oracle-oval
почти 10 лет назад

ELSA-2015-2401: grub2 security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 19%
0.0006
Низкий

2.6 Low

CVSS2