Vulnerability Description
Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grub_username_get function in grub-core/normal/auth.c or the (2) grub_password_get function in lib/crypto.c, which trigger an "Off-by-two" or "Out of bounds overwrite" memory error.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Grub2 | 1.98 |
| Fedoraproject | Fedora | 23 |
Related Weaknesses (CWE)
References
- http://hmarco.org/bugs/CVE-2015-8370-Grub2-authentication-bypass.htmlExploit
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/173703.h
- http://lists.fedoraproject.org/pipermail/package-announce/2015-December/174049.h
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00037.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00039.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00040.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00041.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00043.html
- http://lists.opensuse.org/opensuse-security-announce/2015-12/msg00044.html
- http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00003.html
- http://packetstormsecurity.com/files/134831/Grub2-Authentication-Bypass.html
- http://rhn.redhat.com/errata/RHSA-2015-2623.html
- http://seclists.org/fulldisclosure/2015/Dec/69
- http://www.debian.org/security/2015/dsa-3421
- http://www.openwall.com/lists/oss-security/2015/12/15/6
FAQ
What is CVE-2015-8370?
CVE-2015-8370 is a vulnerability with a CVSS score of 7.4 (HIGH). Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via b...
How severe is CVE-2015-8370?
CVE-2015-8370 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8370?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Grub2, Fedoraproject Fedora.