CVE-2013-4577
Publication date 12 May 2014
Last updated 24 July 2024
Ubuntu priority
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.
Status
Package | Ubuntu Release | Status |
---|---|---|
grub2 | ||
20.04 LTS focal |
Fixed 2.00-20
|
|
18.04 LTS bionic |
Fixed 2.00-20
|
|
16.04 LTS xenial |
Fixed 2.00-20
|
|
14.04 LTS trusty |
Fixed 2.00-20
|
|
Patch details
Package | Patch details |
---|---|
grub2 |