• [SECURITY] [DSA 3421-1] grub2 security update

    From Luciano Bello@1:229/2 to All on Wed Dec 16 21:10:01 2015
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA256

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3421-1 [email protected] https://www.debian.org/security/ Luciano Bello December 16, 2015 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : grub2
    CVE ID : CVE-2015-8370
    Debian Bug : 807614

    Hector Marco and Ismael Ripoll, from Cybersecurity UPV Research Group,
    found an integer underflow vulnerability in Grub2, a popular bootloader.
    A local attacker can bypass the Grub2 authentication by inserting a
    crafted input as username or password.

    More information: http://hmarco.org/bugs/CVE-2015-8370-Grub2-authentication-bypass.html

    For the oldstable distribution (wheezy), this problem has been fixed
    in version 1.99-27+deb7u3.

    For the stable distribution (jessie), this problem has been fixed in
    version 2.02~beta2-22+deb8u1.

    For the unstable distribution (sid), this problem has been fixed in
    version 2.02~beta2-33.

    We recommend that you upgrade your grub2 packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1

    iQIcBAEBCAAGBQJWca2YAAoJEG7C3vaP/jd0dlcP/RhoHne63QfnrnIquCwCZ/QP xaeAcEHt4/4es0+vin1XGBoGQTXN+WcK11sxteoHnrGuI6Wc8JnLbKab/FkvHPKr T/IiXrzqqjbN5LyE1aBRlfucFyIH4t23UEOEalqv5pXuG5Cf3ixVRcapsE2aOP3y 4bz506nn/3wqlnDxQrK1lsLJD1UliT4M4R9r7pAWUm4TAItxamq3f6RQWzhEB4FQ l9mY8pVFQA00V8nrGOrOq50Q2BB8vS/ien+vWns4x34SM1s5CnJtJdqKRoi0CE1n 53+4Q8JgyJv3CEmqXBCfcA5j4lUTErAu2C7voS7UWFpuvTLl/L4b29VvOvBFPdab fXQalh9TPq+SC2U5VIDfz9d+6vNXZrrl9JuEVmJW2obZuDcRuQ46AvMvlIOXliYC rR4Ks6dPVwItaSPPi4zFX1cSqAiIwjNZlOGKDtZMpdOsxQ1S0S4LliAdrDvjFGgi 4z4eX1bj3Rmvt+GEoHax0Hr0rj4NUWeK+eXPHbpREULZk8b5XbX0mHSbyW1FZbiB PUIJVS9x3jEqdCIJgjkQ+0RbF6mgBMebeRJL/jIfUf52GLfxbMsXvcr2syJKdZGm +rP12n+vpZiFSfUbngwnUJYBTT1CNyn3AGJl4QTzbePWXtPQmSAEpeF4okJL7yRL XRbVKamQzx2quRhDq97r
    =OKnv
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)