CVE-2013-4577
Publication date 12 May 2014
Last updated 24 July 2024
Ubuntu priority
Description
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| grub2 | ||
| 20.04 LTS focal |
Fixed 2.00-20
|
|
| 18.04 LTS bionic |
Fixed 2.00-20
|
|
| 16.04 LTS xenial |
Fixed 2.00-20
|
|
| 14.04 LTS trusty |
Fixed 2.00-20
|
|
Patch details
| Package | Patch details |
|---|---|
| grub2 |