Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.844526
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-4432-2)
Summary:The remote host is missing an update for the 'grub2, grub2-signed' package(s) announced via the USN-4432-2 advisory.
Description:Summary:
The remote host is missing an update for the 'grub2, grub2-signed' package(s) announced via the USN-4432-2 advisory.

Vulnerability Insight:
USN-4432-1 fixed vulnerabilities in GRUB2 affecting Secure Boot
environments. Unfortunately, the update introduced regressions for
some BIOS systems (either pre-UEFI or UEFI configured in Legacy mode),
preventing them from successfully booting. This update addresses
the issue.

Users with BIOS systems that installed GRUB2 versions from USN-4432-1
should verify that their GRUB2 installation has a correct understanding
of their boot device location and installed the boot loader correctly.

We apologize for the inconvenience.

Original advisory details:

Jesse Michael and Mickey Shkatov discovered that the configuration parser
in GRUB2 did not properly exit when errors were discovered, resulting in
heap-based buffer overflows. A local attacker could use this to execute
arbitrary code and bypass UEFI Secure Boot restrictions. (CVE-2020-10713)

Chris Coulson discovered that the GRUB2 function handling code did not
properly handle a function being redefined, leading to a use-after-free
vulnerability. A local attacker could use this to execute arbitrary code
and bypass UEFI Secure Boot restrictions. (CVE-2020-15706)

Chris Coulson discovered that multiple integer overflows existed in GRUB2
when handling certain filesystems or font files, leading to heap-based
buffer overflows. A local attacker could use these to execute arbitrary
code and bypass UEFI Secure Boot restrictions. (CVE-2020-14309,
CVE-2020-14310, CVE-2020-14311)

It was discovered that the memory allocator for GRUB2 did not validate
allocation size, resulting in multiple integer overflows and heap-based
buffer overflows when handling certain filesystems, PNG images or disk
metadata. A local attacker could use this to execute arbitrary code and
bypass UEFI Secure Boot restrictions. (CVE-2020-14308)

Mathieu Trudel-Lapierre discovered that in certain situations, GRUB2
failed to validate kernel signatures. A local attacker could use this
to bypass Secure Boot restrictions. (CVE-2020-15705)

Colin Watson and Chris Coulson discovered that an integer overflow
existed in GRUB2 when handling the initrd command, leading to a heap-based
buffer overflow. A local attacker could use this to execute arbitrary code
and bypass UEFI Secure Boot restrictions. (CVE-2020-15707)

Affected Software/OS:
'grub2, grub2-signed' package(s) on Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04.

Solution:
Please install the updated package(s).

CVSS Score:
4.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2020-10713
CERT/CC vulnerability note: VU#174059
https://www.kb.cert.org/vuls/id/174059
Cisco Security Advisory: 20200804 GRUB2 Arbitrary Code Execution Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-grub2-code-exec-xLePCAPY
Debian Security Information: DSA-4735 (Google Search)
https://www.debian.org/security/2020/dsa-4735
https://security.gentoo.org/glsa/202104-05
https://cve.openeuler.org/#/CVEInfo/CVE-2020-10713
https://eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/
https://kb.vmware.com/s/article/80181
https://bugzilla.redhat.com/show_bug.cgi?id=1825243
http://www.openwall.com/lists/oss-security/2020/07/29/3
SuSE Security Announcement: openSUSE-SU-2020:1168 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.html
SuSE Security Announcement: openSUSE-SU-2020:1169 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.html
https://usn.ubuntu.com/4432-1/
Common Vulnerability Exposure (CVE) ID: CVE-2020-14308
https://bugzilla.redhat.com/show_bug.cgi?id=1852009
http://www.openwall.com/lists/oss-security/2021/09/17/2
http://www.openwall.com/lists/oss-security/2021/09/17/4
http://www.openwall.com/lists/oss-security/2021/09/21/1
Common Vulnerability Exposure (CVE) ID: CVE-2020-14309
https://bugzilla.redhat.com/show_bug.cgi?id=1852022
Common Vulnerability Exposure (CVE) ID: CVE-2020-14310
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14310
Common Vulnerability Exposure (CVE) ID: CVE-2020-14311
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14311
Common Vulnerability Exposure (CVE) ID: CVE-2020-15705
https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011
https://www.eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/
https://www.openwall.com/lists/oss-security/2020/07/29/3
Debian Security Information: https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot (Google Search)
https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot
http://www.openwall.com/lists/oss-security/2021/03/02/3
RedHat Security Advisories: https://access.redhat.com/security/vulnerabilities/grub2bootloader
https://access.redhat.com/security/vulnerabilities/grub2bootloader
SuSE Security Announcement: https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/ (Google Search)
https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/
SuSE Security Announcement: https://www.suse.com/support/kb/doc/?id=000019673 (Google Search)
https://www.suse.com/support/kb/doc/?id=000019673
SuSE Security Announcement: openSUSE-SU-2020:1280 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00067.html
SuSE Security Announcement: openSUSE-SU-2020:1282 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00069.html
http://ubuntu.com/security/notices/USN-4432-1
https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass
Common Vulnerability Exposure (CVE) ID: CVE-2020-15706
Common Vulnerability Exposure (CVE) ID: CVE-2020-15707
CopyrightCopyright (C) 2020 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.