CVE-2015-8370

Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grub_username_get function in grub-core/normal/auth.c or the (2) grub_password_get function in lib/crypto.c, which trigger an "Off-by-two" or "Out of bounds overwrite" memory error.
Wrap or Wraparound
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
Affected Products (NVD)
VendorProductVersion
gnugrub2
1.98
gnugrub2
1.99
gnugrub2
2.00
gnugrub2
2.01
gnugrub2
2.02
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
grub2
bookworm
2.06-13+deb12u1
fixed
bookworm (security)
2.06-13+deb12u1
fixed
bullseye
2.06-3~deb11u6
fixed
bullseye (security)
2.06-3~deb11u6
fixed
sid
2.12-5
fixed
trixie
2.12-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
grub2
precise
Fixed 1.99-21ubuntu3.19
released
trusty
Fixed 2.02~beta2-9ubuntu1.6
released
vivid
Fixed 2.02~beta2-22ubuntu1.4
released
wily
Fixed 2.02~beta2-29ubuntu0.2
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
grub2
suse enterprise desktop 15
2.02-17.4
fixed
suse enterprise desktop 15 SP1
2.02-24.12
fixed
suse enterprise desktop 15 SP2
2.04-7.9
fixed
suse enterprise desktop 15 SP3
2.04-20.4
fixed
suse enterprise desktop 15 SP4
2.06-150400.9.9
fixed
suse enterprise desktop 15 SP5
2.06-150500.27.4
fixed
suse enterprise desktop 15 SP6
2.12-150600.6.13
fixed
suse enterprise desktop 15 SP7
2.12-150700.17.4
fixed
suse enterprise sap 15
2.02-17.4
fixed
suse enterprise sap 15 SP1
2.02-24.12
fixed
suse enterprise sap 15 SP2
2.04-7.9
fixed
suse enterprise sap 15 SP3
2.04-20.4
fixed
suse enterprise sap 15 SP4
2.06-150400.9.9
fixed
suse enterprise sap 15 SP5
2.06-150500.27.4
fixed
suse enterprise sap 15 SP6
2.12-150600.6.13
fixed
suse enterprise sap 15 SP7
2.12-150700.17.4
fixed
suse enterprise server 15
2.02-17.4
fixed
suse enterprise server 15 SP1
2.02-24.12
fixed
suse enterprise server 15 SP2
2.04-7.9
fixed
suse enterprise server 15 SP3
2.04-20.4
fixed
suse enterprise server 15 SP4
2.06-150400.9.9
fixed
suse enterprise server 15 SP5
2.06-150500.27.4
fixed
suse enterprise server 15 SP6
2.12-150600.6.13
fixed
suse enterprise server 15 SP7
2.12-150700.17.4
fixed
grub2-arm64-efi
suse enterprise desktop 15 SP2
2.04-7.9
fixed
suse enterprise desktop 15 SP3
2.04-20.4
fixed
suse enterprise desktop 15 SP4
2.06-150400.9.9
fixed
suse enterprise desktop 15 SP5
2.06-150500.27.4
fixed
suse enterprise desktop 15 SP6
2.12-150600.6.13
fixed
suse enterprise desktop 15 SP7
2.12-150700.17.4
fixed
suse enterprise sap 15 SP2
2.04-7.9
fixed
suse enterprise sap 15 SP3
2.04-20.4
fixed
suse enterprise sap 15 SP4
2.06-150400.9.9
fixed
suse enterprise sap 15 SP5
2.06-150500.27.4
fixed
suse enterprise sap 15 SP6
2.12-150600.6.13
fixed
suse enterprise sap 15 SP7
2.12-150700.17.4
fixed
suse enterprise server 15 SP2
2.04-7.9
fixed
suse enterprise server 15 SP3
2.04-20.4
fixed
suse enterprise server 15 SP4
2.06-150400.9.9
fixed
suse enterprise server 15 SP5
2.06-150500.27.4
fixed
suse enterprise server 15 SP6
2.12-150600.6.13
fixed
suse enterprise server 15 SP7
2.12-150700.17.4
fixed
grub2-i386-pc
suse enterprise desktop 15
2.02-17.4
fixed
suse enterprise desktop 15 SP1
2.02-24.12
fixed
suse enterprise desktop 15 SP2
2.04-7.9
fixed
suse enterprise desktop 15 SP3
2.04-20.4
fixed
suse enterprise desktop 15 SP4
2.06-150400.9.9
fixed
suse enterprise desktop 15 SP5
2.06-150500.27.4
fixed
suse enterprise desktop 15 SP6
2.12-150600.6.13
fixed
suse enterprise desktop 15 SP7
2.12-150700.17.4
fixed
suse enterprise sap 15
2.02-17.4
fixed
suse enterprise sap 15 SP1
2.02-24.12
fixed
suse enterprise sap 15 SP2
2.04-7.9
fixed
suse enterprise sap 15 SP3
2.04-20.4
fixed
suse enterprise sap 15 SP4
2.06-150400.9.9
fixed
suse enterprise sap 15 SP5
2.06-150500.27.4
fixed
suse enterprise sap 15 SP6
2.12-150600.6.13
fixed
suse enterprise sap 15 SP7
2.12-150700.17.4
fixed
suse enterprise server 15
2.02-17.4
fixed
suse enterprise server 15 SP1
2.02-24.12
fixed
suse enterprise server 15 SP2
2.04-7.9
fixed
suse enterprise server 15 SP3
2.04-20.4
fixed
suse enterprise server 15 SP4
2.06-150400.9.9
fixed
suse enterprise server 15 SP5
2.06-150500.27.4
fixed
suse enterprise server 15 SP6
2.12-150600.6.13
fixed
suse enterprise server 15 SP7
2.12-150700.17.4
fixed
grub2-powerpc-ieee1275
suse enterprise desktop 15 SP1
2.02-24.12
fixed
suse enterprise desktop 15 SP2
2.04-7.9
fixed
suse enterprise desktop 15 SP3
2.04-20.4
fixed
suse enterprise desktop 15 SP4
2.06-150400.9.9
fixed
suse enterprise desktop 15 SP5
2.06-150500.27.4
fixed
suse enterprise desktop 15 SP6
2.12-150600.6.13
fixed
suse enterprise desktop 15 SP7
2.12-150700.17.4
fixed
suse enterprise sap 15 SP1
2.02-24.12
fixed
suse enterprise sap 15 SP2
2.04-7.9
fixed
suse enterprise sap 15 SP3
2.04-20.4
fixed
suse enterprise sap 15 SP4
2.06-150400.9.9
fixed
suse enterprise sap 15 SP5
2.06-150500.27.4
fixed
suse enterprise sap 15 SP6
2.12-150600.6.13
fixed
suse enterprise sap 15 SP7
2.12-150700.17.4
fixed
suse enterprise server 15 SP1
2.02-24.12
fixed
suse enterprise server 15 SP2
2.04-7.9
fixed
suse enterprise server 15 SP3
2.04-20.4
fixed
suse enterprise server 15 SP4
2.06-150400.9.9
fixed
suse enterprise server 15 SP5
2.06-150500.27.4
fixed
suse enterprise server 15 SP6
2.12-150600.6.13
fixed
suse enterprise server 15 SP7
2.12-150700.17.4
fixed
grub2-s390x-emu
suse enterprise desktop 15 SP1
2.02-24.12
fixed
suse enterprise desktop 15 SP2
2.04-7.9
fixed
suse enterprise desktop 15 SP3
2.04-20.4
fixed
suse enterprise desktop 15 SP4
2.06-150400.9.9
fixed
suse enterprise desktop 15 SP5
2.06-150500.27.4
fixed
suse enterprise desktop 15 SP6
2.12-150600.6.13
fixed
suse enterprise desktop 15 SP7
2.12-150700.17.4
fixed
suse enterprise sap 15 SP1
2.02-24.12
fixed
suse enterprise sap 15 SP2
2.04-7.9
fixed
suse enterprise sap 15 SP3
2.04-20.4
fixed
suse enterprise sap 15 SP4
2.06-150400.9.9
fixed
suse enterprise sap 15 SP5
2.06-150500.27.4
fixed
suse enterprise sap 15 SP6
2.12-150600.6.13
fixed
suse enterprise sap 15 SP7
2.12-150700.17.4
fixed
suse enterprise server 15 SP1
2.02-24.12
fixed
suse enterprise server 15 SP2
2.04-7.9
fixed
suse enterprise server 15 SP3
2.04-20.4
fixed
suse enterprise server 15 SP4
2.06-150400.9.9
fixed
suse enterprise server 15 SP5
2.06-150500.27.4
fixed
suse enterprise server 15 SP6
2.12-150600.6.13
fixed
suse enterprise server 15 SP7
2.12-150700.17.4
fixed
grub2-snapper-plugin
suse enterprise desktop 15
2.02-17.4
fixed
suse enterprise desktop 15 SP1
2.02-24.12
fixed
suse enterprise desktop 15 SP2
2.04-7.9
fixed
suse enterprise desktop 15 SP3
2.04-20.4
fixed
suse enterprise desktop 15 SP4
2.06-150400.9.9
fixed
suse enterprise desktop 15 SP5
2.06-150500.27.4
fixed
suse enterprise desktop 15 SP6
2.12-150600.6.13
fixed
suse enterprise desktop 15 SP7
2.12-150700.17.4
fixed
suse enterprise sap 15
2.02-17.4
fixed
suse enterprise sap 15 SP1
2.02-24.12
fixed
suse enterprise sap 15 SP2
2.04-7.9
fixed
suse enterprise sap 15 SP3
2.04-20.4
fixed
suse enterprise sap 15 SP4
2.06-150400.9.9
fixed
suse enterprise sap 15 SP5
2.06-150500.27.4
fixed
suse enterprise sap 15 SP6
2.12-150600.6.13
fixed
suse enterprise sap 15 SP7
2.12-150700.17.4
fixed
suse enterprise server 15
2.02-17.4
fixed
suse enterprise server 15 SP1
2.02-24.12
fixed
suse enterprise server 15 SP2
2.04-7.9
fixed
suse enterprise server 15 SP3
2.04-20.4
fixed
suse enterprise server 15 SP4
2.06-150400.9.9
fixed
suse enterprise server 15 SP5
2.06-150500.27.4
fixed
suse enterprise server 15 SP6
2.12-150600.6.13
fixed
suse enterprise server 15 SP7
2.12-150700.17.4
fixed
grub2-systemd-sleep-plugin
suse enterprise desktop 15
2.02-17.4
fixed
suse enterprise desktop 15 SP1
2.02-24.12
fixed
suse enterprise desktop 15 SP2
2.04-7.9
fixed
suse enterprise desktop 15 SP3
2.04-20.4
fixed
suse enterprise desktop 15 SP4
2.06-150400.9.9
fixed
suse enterprise desktop 15 SP5
2.06-150500.27.4
fixed
suse enterprise desktop 15 SP6
2.12-150600.6.13
fixed
suse enterprise desktop 15 SP7
2.12-150700.17.4
fixed
suse enterprise sap 15
2.02-17.4
fixed
suse enterprise sap 15 SP1
2.02-24.12
fixed
suse enterprise sap 15 SP2
2.04-7.9
fixed
suse enterprise sap 15 SP3
2.04-20.4
fixed
suse enterprise sap 15 SP4
2.06-150400.9.9
fixed
suse enterprise sap 15 SP5
2.06-150500.27.4
fixed
suse enterprise sap 15 SP6
2.12-150600.6.13
fixed
suse enterprise sap 15 SP7
2.12-150700.17.4
fixed
suse enterprise server 15
2.02-17.4
fixed
suse enterprise server 15 SP1
2.02-24.12
fixed
suse enterprise server 15 SP2
2.04-7.9
fixed
suse enterprise server 15 SP3
2.04-20.4
fixed
suse enterprise server 15 SP4
2.06-150400.9.9
fixed
suse enterprise server 15 SP5
2.06-150500.27.4
fixed
suse enterprise server 15 SP6
2.12-150600.6.13
fixed
suse enterprise server 15 SP7
2.12-150700.17.4
fixed
grub2-x86_64-efi
suse enterprise desktop 15
2.02-17.4
fixed
suse enterprise desktop 15 SP1
2.02-24.12
fixed
suse enterprise desktop 15 SP2
2.04-7.9
fixed
suse enterprise desktop 15 SP3
2.04-20.4
fixed
suse enterprise desktop 15 SP4
2.06-150400.9.9
fixed
suse enterprise desktop 15 SP5
2.06-150500.27.4
fixed
suse enterprise desktop 15 SP6
2.12-150600.6.13
fixed
suse enterprise desktop 15 SP7
2.12-150700.17.4
fixed
suse enterprise sap 15
2.02-17.4
fixed
suse enterprise sap 15 SP1
2.02-24.12
fixed
suse enterprise sap 15 SP2
2.04-7.9
fixed
suse enterprise sap 15 SP3
2.04-20.4
fixed
suse enterprise sap 15 SP4
2.06-150400.9.9
fixed
suse enterprise sap 15 SP5
2.06-150500.27.4
fixed
suse enterprise sap 15 SP6
2.12-150600.6.13
fixed
suse enterprise sap 15 SP7
2.12-150700.17.4
fixed
suse enterprise server 15
2.02-17.4
fixed
suse enterprise server 15 SP1
2.02-24.12
fixed
suse enterprise server 15 SP2
2.04-7.9
fixed
suse enterprise server 15 SP3
2.04-20.4
fixed
suse enterprise server 15 SP4
2.06-150400.9.9
fixed
suse enterprise server 15 SP5
2.06-150500.27.4
fixed
suse enterprise server 15 SP6
2.12-150600.6.13
fixed
suse enterprise server 15 SP7
2.12-150700.17.4
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
grub2
RHEL 7
1:2.02-0.33.el7_2
fixed
grub2-efi
RHEL 7
1:2.02-0.33.el7_2
fixed
grub2-efi-modules
RHEL 7
1:2.02-0.33.el7_2
fixed
grub2-tools
RHEL 7
1:2.02-0.33.el7_2
fixed
References