![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.844526 |
Category: | Ubuntu Local Security Checks |
Title: | Ubuntu: Security Advisory (USN-4432-2) |
Summary: | The remote host is missing an update for the 'grub2, grub2-signed' package(s) announced via the USN-4432-2 advisory. |
Description: | Summary: The remote host is missing an update for the 'grub2, grub2-signed' package(s) announced via the USN-4432-2 advisory. Vulnerability Insight: USN-4432-1 fixed vulnerabilities in GRUB2 affecting Secure Boot environments. Unfortunately, the update introduced regressions for some BIOS systems (either pre-UEFI or UEFI configured in Legacy mode), preventing them from successfully booting. This update addresses the issue. Users with BIOS systems that installed GRUB2 versions from USN-4432-1 should verify that their GRUB2 installation has a correct understanding of their boot device location and installed the boot loader correctly. We apologize for the inconvenience. Original advisory details: Jesse Michael and Mickey Shkatov discovered that the configuration parser in GRUB2 did not properly exit when errors were discovered, resulting in heap-based buffer overflows. A local attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. (CVE-2020-10713) Chris Coulson discovered that the GRUB2 function handling code did not properly handle a function being redefined, leading to a use-after-free vulnerability. A local attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. (CVE-2020-15706) Chris Coulson discovered that multiple integer overflows existed in GRUB2 when handling certain filesystems or font files, leading to heap-based buffer overflows. A local attacker could use these to execute arbitrary code and bypass UEFI Secure Boot restrictions. (CVE-2020-14309, CVE-2020-14310, CVE-2020-14311) It was discovered that the memory allocator for GRUB2 did not validate allocation size, resulting in multiple integer overflows and heap-based buffer overflows when handling certain filesystems, PNG images or disk metadata. A local attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. (CVE-2020-14308) Mathieu Trudel-Lapierre discovered that in certain situations, GRUB2 failed to validate kernel signatures. A local attacker could use this to bypass Secure Boot restrictions. (CVE-2020-15705) Colin Watson and Chris Coulson discovered that an integer overflow existed in GRUB2 when handling the initrd command, leading to a heap-based buffer overflow. A local attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. (CVE-2020-15707) Affected Software/OS: 'grub2, grub2-signed' package(s) on Ubuntu 14.04, Ubuntu 16.04, Ubuntu 18.04, Ubuntu 20.04. Solution: Please install the updated package(s). CVSS Score: 4.6 CVSS Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2020-10713 CERT/CC vulnerability note: VU#174059 https://www.kb.cert.org/vuls/id/174059 Cisco Security Advisory: 20200804 GRUB2 Arbitrary Code Execution Vulnerability https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-grub2-code-exec-xLePCAPY Debian Security Information: DSA-4735 (Google Search) https://www.debian.org/security/2020/dsa-4735 https://security.gentoo.org/glsa/202104-05 https://cve.openeuler.org/#/CVEInfo/CVE-2020-10713 https://eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/ https://kb.vmware.com/s/article/80181 https://bugzilla.redhat.com/show_bug.cgi?id=1825243 http://www.openwall.com/lists/oss-security/2020/07/29/3 SuSE Security Announcement: openSUSE-SU-2020:1168 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.html SuSE Security Announcement: openSUSE-SU-2020:1169 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.html https://usn.ubuntu.com/4432-1/ Common Vulnerability Exposure (CVE) ID: CVE-2020-14308 https://bugzilla.redhat.com/show_bug.cgi?id=1852009 http://www.openwall.com/lists/oss-security/2021/09/17/2 http://www.openwall.com/lists/oss-security/2021/09/17/4 http://www.openwall.com/lists/oss-security/2021/09/21/1 Common Vulnerability Exposure (CVE) ID: CVE-2020-14309 https://bugzilla.redhat.com/show_bug.cgi?id=1852022 Common Vulnerability Exposure (CVE) ID: CVE-2020-14310 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14310 Common Vulnerability Exposure (CVE) ID: CVE-2020-14311 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14311 Common Vulnerability Exposure (CVE) ID: CVE-2020-15705 https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.html https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011 https://www.eclypsium.com/2020/07/29/theres-a-hole-in-the-boot/ https://www.openwall.com/lists/oss-security/2020/07/29/3 Debian Security Information: https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot (Google Search) https://www.debian.org/security/2020-GRUB-UEFI-SecureBoot http://www.openwall.com/lists/oss-security/2021/03/02/3 RedHat Security Advisories: https://access.redhat.com/security/vulnerabilities/grub2bootloader https://access.redhat.com/security/vulnerabilities/grub2bootloader SuSE Security Announcement: https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/ (Google Search) https://www.suse.com/c/suse-addresses-grub2-secure-boot-issue/ SuSE Security Announcement: https://www.suse.com/support/kb/doc/?id=000019673 (Google Search) https://www.suse.com/support/kb/doc/?id=000019673 SuSE Security Announcement: openSUSE-SU-2020:1280 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00067.html SuSE Security Announcement: openSUSE-SU-2020:1282 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00069.html http://ubuntu.com/security/notices/USN-4432-1 https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass Common Vulnerability Exposure (CVE) ID: CVE-2020-15706 Common Vulnerability Exposure (CVE) ID: CVE-2020-15707 |
Copyright | Copyright (C) 2020 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |