Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2015:2386-1

Опубликовано: 29 дек. 2015
Источник: suse-cvrf

Описание

Security update for grub2

This update for grub2 provides the following fixes:

A security issues with a bufferoverflow when reading username and password was fixed (bsc#956631, CVE-2015-8370)

Bugs fixed:

  • Expand list of grub.cfg search path in PV Xen guests for systems installed on btrfs snapshots. (bsc#946148, bsc#952539)
  • Add grub.xen config searching path on boot partition. (bsc#884828)
  • Add linux16 and initrd16 to grub.xen. (bsc#884830)

Список пакетов

SUSE Linux Enterprise Desktop 11 SP3
grub2-x86_64-efi-2.00-0.49.2
grub2-x86_64-xen-2.00-0.49.2
SUSE Linux Enterprise Server 11 SP3
grub2-x86_64-efi-2.00-0.49.2
grub2-x86_64-xen-2.00-0.49.2
SUSE Linux Enterprise Server 11 SP3-TERADATA
grub2-x86_64-efi-2.00-0.49.2
grub2-x86_64-xen-2.00-0.49.2
SUSE Linux Enterprise Server for SAP Applications 11 SP3
grub2-x86_64-efi-2.00-0.49.2
grub2-x86_64-xen-2.00-0.49.2

Описание

Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grub_username_get function in grub-core/normal/auth.c or the (2) grub_password_get function in lib/crypto.c, which trigger an "Off-by-two" or "Out of bounds overwrite" memory error.


Затронутые продукты
SUSE Linux Enterprise Desktop 11 SP3:grub2-x86_64-efi-2.00-0.49.2
SUSE Linux Enterprise Desktop 11 SP3:grub2-x86_64-xen-2.00-0.49.2
SUSE Linux Enterprise Server 11 SP3-TERADATA:grub2-x86_64-efi-2.00-0.49.2
SUSE Linux Enterprise Server 11 SP3-TERADATA:grub2-x86_64-xen-2.00-0.49.2

Ссылки