Login
Newsletter
Werbung

Sicherheit: Pufferüberlauf in GRUB
Aktuelle Meldungen Distributionen
Name: Pufferüberlauf in GRUB
ID: USN-2836-1
Distribution: Ubuntu
Plattformen: Ubuntu 12.04 LTS, Ubuntu 14.04 LTS, Ubuntu 15.04, Ubuntu 15.10
Datum: Di, 15. Dezember 2015, 22:48
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8370
Applikationen: GRUB

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============6251344557133485984==
Content-Type: multipart/signed; micalg=pgp-sha512;
protocol="application/pgp-signature";
boundary="AfQqDBhRlSDNtgQ1dfrLNfRDVHQMHKaw9"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--AfQqDBhRlSDNtgQ1dfrLNfRDVHQMHKaw9
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-2836-1
December 15, 2015

grub2 vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 15.04
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

GRUB password protection can be bypassed.

Software Description:
- grub2: GRand Unified Bootloader

Details:

Hector Marco and Ismael Ripoll discovered that GRUB incorrectly handled
the backspace key when configured to use authentication. A local attacker
could use this issue to bypass GRUB password protection.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
grub2-common 2.02~beta2-29ubuntu0.2

Ubuntu 15.04:
grub2-common 2.02~beta2-22ubuntu1.4

Ubuntu 14.04 LTS:
grub2-common 2.02~beta2-9ubuntu1.6

Ubuntu 12.04 LTS:
grub2-common 1.99-21ubuntu3.19

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2836-1
CVE-2015-8370

Package Information:
https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-29ubuntu0.2
https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-22ubuntu1.4
https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6
https://launchpad.net/ubuntu/+source/grub2/1.99-21ubuntu3.19



--AfQqDBhRlSDNtgQ1dfrLNfRDVHQMHKaw9
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJWcHEjAAoJEGVp2FWnRL6TnZsP/2Ke8EtOIYXPuSjq1JR+CAs+
7KQhc2WWMYjnKzF3kHzi782cV7mDX99XswcFJq1vs6txoGk1J2S+I8LeyccGKGBK
HOUNUBbvjIbjxX0wZubklfM2LLuX/6Zgn9lTIIym8PA4K8b17K99/NciQDrmVaa8
+jtPyA9GWYYUc3Fx11uSWeC8KprqbSsHi4tQBQgS4F4SbyFn8cC13+aserLyF3eS
h4VabcXB6tydT5FlAbd2nFXPCumvGkt7Q8fPScXISk9Z2jwmZ4yjer5ok0Zog8dH
Uy9viCJq0GHuUwUQJBX1WvaHIH6OTQj4AjcrGrA7ZXmIo2VNUV5PjqMQYU+8cALa
0u6d3spKfMK+KKo0m1jwY4tFfOx5/MlREnCvhM8rEJHKo4goBZ+3k2sWLHr/0Aur
vUq1auFvtfShANXZaqs202Cqwq1YNSD2Lyth3ddG7M11MRbkvL1UyIjabN+oz3rx
wqTeUtzlrgQNekN8K7QJfiEfJ/kuM5hK505c+Sqn1c6dhAxXFTXBD0YtDebNGQuy
jnyiUulfhNSkOLvrUKFY3EnTwH2kb95phd2YuKc3AM5IkHExDS9FOEajZFpFUkSo
gQnaw/w+X5G70rq8MgD7GDqmXve+Hocmem2I3s4Q09ZvgKNLdwIQ7pZ/S1gQBcAC
5Xc0d8fCEp5OvZeXyPwu
=hWmL
-----END PGP SIGNATURE-----

--AfQqDBhRlSDNtgQ1dfrLNfRDVHQMHKaw9--


--===============6251344557133485984==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============6251344557133485984==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung