LWN.net Logo

grub2: authentication bypass

Package(s):grub2 CVE #(s):CVE-2009-4128
Created:December 9, 2009 Updated:December 9, 2009
Description:

From the Ubuntu advisory:

It was discovered that GRUB 2 did not properly validate passwords. An attacker with physical access could conduct a brute force attack and bypass authentication by submitting a 1 character password.

Alerts:
Ubuntu USN-868-1 2009-12-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds