Lucene search

K
nvd[email protected]NVD:CVE-2015-8370
HistoryDec 16, 2015 - 9:59 p.m.

CVE-2015-8370

2015-12-1621:59:04
CWE-264
web.nvd.nist.gov

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.9%

Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grub_username_get function in grub-core/normal/auth.c or the (2) grub_password_get function in lib/crypto.c, which trigger an “Off-by-two” or “Out of bounds overwrite” memory error.

Affected configurations

NVD
Node
gnugrub2Match1.98
OR
gnugrub2Match1.99
OR
gnugrub2Match2.00
OR
gnugrub2Match2.01
OR
gnugrub2Match2.02
Node
fedoraprojectfedoraMatch23

References

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.9%