2.1
CVSSv2

CVE-2013-4577

Published: 12/05/2014 Updated: 16/01/2024
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu grub -

Vendor Advisories

Debian Bug report logs - #632598 grub-mkconfig: CVE-2013-4577: should set safer permissions even when hashed passwords are found Package: grub-common; Maintainer for grub-common is GRUB Maintainers <pkg-grub-devel@alioth-listsdebiannet>; Source for grub-common is src:grub2 (PTS, buildd, popcon) Reported by: "Francesco Poli ...