PT-2015-2740 · Red Hat+1 · Grub2+2

Stefan Cornelius

·

Publicado

2015-11-19

·

Atualizado

2016-12-07

·

CVE-2015-5281

CVSS v2.0

2.6

Baixa

VetorAV:L/AC:H/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7
Description The issue allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted multiboot or multiboot2 module in the configuration file. Physically proximate attackers can also bypass intended Secure Boot restrictions and execute non-verified code via the boot menu. The vulnerability is related to insufficient access control to files.
Recommendations For grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, update to a version 2.02-0.29 or later to resolve the issue. As a temporary workaround, consider restricting access to the configuration file and the boot menu to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-12105
CESA-2015_2401
CVE-2015-5281
RHSA-2015:2401
RHSA-2015_2401

Produtos afetados

Centos
Red Hat
Grub2