|
|
| |
|
| |
grub2: insecure permissions in bootloader configuration
| Package(s): | grub2 |
CVE #(s): | CVE-2012-2314
|
| Created: | May 10, 2012 |
Updated: | May 16, 2012 |
| Description: |
From the Red Hat bugzilla entry:
A security flaw was found in the way bootloader configuration module of
Anaconda, a graphical system installer, stored password hashes when performing
write of password configuration file (0755 permissions were used instead of
0700 ones). A local users could use this flaw to obtain password hashes and
conduct brute force password guessing attacks (possibly leading to password
circumvention, machine reboot or use of custom kernel or initrd command line
parameters).
|
| Alerts: |
|
( Log in to post comments)
|
|
|