CVE-2009-4128
published 2009-12-01CVE-2009-4128: GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for physically…
PriorityP430high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.57%
43.8th percentile
GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for physically proximate attackers to conduct brute force attacks and bypass authentication by submitting a password whose length is 1.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub | < grub2 1.97+20091115-1 (bookworm) | grub2 1.97+20091115-1 (bookworm) |
| debian | grub2 | < grub2 1.97+20091115-1 (bookworm) | grub2 1.97+20091115-1 (bookworm) |
| gnu | grub2 | >= 0 < 1.97+20091115-1 | 1.97+20091115-1 |
| gnu | grub2 | >= 0 < 1.97+20091115-1 | 1.97+20091115-1 |
| gnu | grub2 | >= 0 < 1.97+20091115-1 | 1.97+20091115-1 |
| gnu | grub2 | >= 0 < 1.97+20091115-1 | 1.97+20091115-1 |
| gnu | grub_2 | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GRUB 2 vulnerability
vendor_ubuntu·2009-12-09
CVE-2009-4128 GRUB 2 vulnerability
Title: GRUB 2 vulnerability
Summary: GRUB 2 vulnerability
It was discovered that GRUB 2 did not properly validate passwords. An
attacker with physical access could conduct a brute force attack and bypass
authentication by submitting a 1 character password.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Users who have upgraded from GRUB Legacy to GRUB 2 and did not run
'upgrade-from-grub-legacy' (ie those who are still using Grub Legacy to
chainload into GRUB 2) will have to run the following command (possibly
adjusting 'hd0') to update GRUB 2's on disk core image:
$ sudo grub-install --no-floppy --grub-setup=/bin/true "(hd0)"
Red Hat
grub2: Improper password checking
vendor_redhat·2009-11-08·CVSS 7.2
CVE-2009-4128 [HIGH] grub2: Improper password checking
grub2: Improper password checking
GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for physically proximate attackers to conduct brute force attacks and bypass authentication by submitting a password whose length is 1.
Debian
CVE-2009-4128: grub - GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion o...
vendor_debian·2009·CVSS 7.2
CVE-2009-4128 [HIGH] CVE-2009-4128: grub - GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion o...
GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for physically proximate attackers to conduct brute force attacks and bypass authentication by submitting a password whose length is 1.
Scope: local
bookworm: resolved
bullseye: resolved
trixie: resolved
GHSA
GHSA-prgr-9xf7-v9fw: GNU GRand Unified Bootloader (GRUB) 2 1
ghsa_unreviewed·2022-05-02
CVE-2009-4128 [HIGH] CWE-287 GHSA-prgr-9xf7-v9fw: GNU GRand Unified Bootloader (GRUB) 2 1
GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for physically proximate attackers to conduct brute force attacks and bypass authentication by submitting a password whose length is 1.
OSV
CVE-2009-4128: GNU GRand Unified Bootloader (GRUB) 2 1
osv·2009-12-01·CVSS 7.2
CVE-2009-4128 [HIGH] CVE-2009-4128: GNU GRand Unified Bootloader (GRUB) 2 1
GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for physically proximate attackers to conduct brute force attacks and bypass authentication by submitting a password whose length is 1.
No detection rules found.
No public exploits indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=555195http://www.openwall.com/lists/oss-security/2024/01/15/3http://www.securityfocus.com/bid/36968https://exchange.xforce.ibmcloud.com/vulnerabilities/54210http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=555195http://www.openwall.com/lists/oss-security/2024/01/15/3http://www.securityfocus.com/bid/36968https://exchange.xforce.ibmcloud.com/vulnerabilities/54210
2009-12-01
Published