LWN.net Logo

grub2: insecure permissions in bootloader configuration

Package(s):grub2 CVE #(s):CVE-2012-2314
Created:May 10, 2012 Updated:May 16, 2012
Description:

From the Red Hat bugzilla entry:

A security flaw was found in the way bootloader configuration module of Anaconda, a graphical system installer, stored password hashes when performing write of password configuration file (0755 permissions were used instead of 0700 ones). A local users could use this flaw to obtain password hashes and conduct brute force password guessing attacks (possibly leading to password circumvention, machine reboot or use of custom kernel or initrd command line parameters).

Alerts:
Fedora FEDORA-2012-7579 2012-05-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds