Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grubusernameget function in grub-core/normal/auth.c or the (2) grubpasswordget function in lib/crypto.c, which trigger an "Off-by-two" or "Out of bounds overwrite" memory error.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-common" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-common-dbgsym" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-coreboot" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-coreboot-bin" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-coreboot-dbg" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-efi" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-efi-amd64" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-efi-amd64-bin" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-efi-amd64-dbg" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-efi-arm" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-efi-arm-bin" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-efi-arm-dbg" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-efi-arm64" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-efi-arm64-bin" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-efi-arm64-dbg" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-efi-ia32" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-efi-ia32-bin" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-efi-ia32-dbg" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-emu" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-emu-dbg" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-emu-dbgsym" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-firmware-qemu" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-ieee1275" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-ieee1275-bin" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-ieee1275-dbg" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-linuxbios" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-mount-udeb" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-mount-udeb-dbgsym" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-pc" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-pc-bin" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-pc-bin-dbgsym" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-pc-dbg" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-rescue-pc" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-theme-starfield" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-uboot" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-uboot-bin" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-uboot-dbg" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-xen" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-xen-bin" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub-xen-dbg" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub2" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub2-common" }, { "binary_version": "2.02~beta2-9ubuntu1.6", "binary_name": "grub2-common-dbgsym" } ] }