CVE Vulnerabilities

CVE-2013-4577

Published: May 12, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.

Affected Software

NameVendorStart VersionEnd Version
GrubGnu- (including)- (including)
Grub2Ubuntuartful*
Grub2Ubuntubionic*
Grub2Ubuntucosmic*
Grub2Ubuntudevel*
Grub2Ubuntudisco*
Grub2Ubuntueoan*
Grub2Ubuntuesm-infra-legacy/trusty*
Grub2Ubuntuesm-infra/bionic*
Grub2Ubuntuesm-infra/focal*
Grub2Ubuntuesm-infra/xenial*
Grub2Ubuntufocal*
Grub2Ubuntugroovy*
Grub2Ubuntuhirsute*
Grub2Ubuntulucid*
Grub2Ubuntuprecise*
Grub2Ubuntuprecise/esm*
Grub2Ubuntuquantal*
Grub2Ubunturaring*
Grub2Ubuntusaucy*
Grub2Ubuntutrusty*
Grub2Ubuntutrusty/esm*
Grub2Ubuntuupstream*
Grub2Ubuntuutopic*
Grub2Ubuntuvivid*
Grub2Ubuntuvivid/ubuntu-core*
Grub2Ubuntuwily*
Grub2Ubuntuxenial*
Grub2Ubuntuyakkety*
Grub2Ubuntuzesty*

References