==========================================================================
Ubuntu Security Notice USN-2836-1
December 15, 2015
grub2 vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 15.10
– Ubuntu 15.04
– Ubuntu 14.04 LTS
– Ubuntu 12.04 LTS
Summary:
GRUB password protection can be bypassed.
Software Description:
– grub2: GRand Unified Bootloader
Details:
Hector Marco and Ismael Ripoll discovered that GRUB incorrectly handled
the backspace key when configured to use authentication. A local attacker
could use this issue to bypass GRUB password protection.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 15.10:
grub2-common 2.02~beta2-29ubuntu0.2
Ubuntu 15.04:
grub2-common 2.02~beta2-22ubuntu1.4
Ubuntu 14.04 LTS:
grub2-common 2.02~beta2-9ubuntu1.6
Ubuntu 12.04 LTS:
grub2-common 1.99-21ubuntu3.19
After a standard system update you need to reboot your computer to make
all the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2836-1
CVE-2015-8370
Package Information:
https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-29ubuntu0.2
https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-22ubuntu1.4
https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6
https://launchpad.net/ubuntu/+source/grub2/1.99-21ubuntu3.19
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2
iQIcBAEBCgAGBQJWcHEjAAoJEGVp2FWnRL6TnZsP/2Ke8EtOIYXPuSjq1JR+CAs+
7KQhc2WWMYjnKzF3kHzi782cV7mDX99XswcFJq1vs6txoGk1J2S+I8LeyccGKGBK
HOUNUBbvjIbjxX0wZubklfM2LLuX/6Zgn9lTIIym8PA4K8b17K99/NciQDrmVaa8
+jtPyA9GWYYUc3Fx11uSWeC8KprqbSsHi4tQBQgS4F4SbyFn8cC13+aserLyF3eS
h4VabcXB6tydT5FlAbd2nFXPCumvGkt7Q8fPScXISk9Z2jwmZ4yjer5ok0Zog8dH
Uy9viCJq0GHuUwUQJBX1WvaHIH6OTQj4AjcrGrA7ZXmIo2VNUV5PjqMQYU+8cALa
0u6d3spKfMK+KKo0m1jwY4tFfOx5/MlREnCvhM8rEJHKo4goBZ+3k2sWLHr/0Aur
vUq1auFvtfShANXZaqs202Cqwq1YNSD2Lyth3ddG7M11MRbkvL1UyIjabN+oz3rx
wqTeUtzlrgQNekN8K7QJfiEfJ/kuM5hK505c+Sqn1c6dhAxXFTXBD0YtDebNGQuy
jnyiUulfhNSkOLvrUKFY3EnTwH2kb95phd2YuKc3AM5IkHExDS9FOEajZFpFUkSo
gQnaw/w+X5G70rq8MgD7GDqmXve+Hocmem2I3s4Q09ZvgKNLdwIQ7pZ/S1gQBcAC
5Xc0d8fCEp5OvZeXyPwu
=hWmL
—–END PGP SIGNATURE—–
—