CVE-2013-4577
published 2014-05-12CVE-2013-4577: A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.38%
30.7th percentile
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | grub2 | < grub2 2.00-20 (bookworm) | grub2 2.00-20 (bookworm) |
| gnu | grub2 | >= 0 < 2.00-20 | 2.00-20 |
| gnu | grub2 | >= 0 < 2.00-20 | 2.00-20 |
| gnu | grub2 | >= 0 < 2.00-20 | 2.00-20 |
| gnu | grub2 | >= 0 < 2.00-20 | 2.00-20 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2mm6-f25m-73r7: A certain Debian patch for GNU GRUB uses world-readable permissions for grub
ghsa_unreviewed·2022-05-17
CVE-2013-4577 [LOW] GHSA-2mm6-f25m-73r7: A certain Debian patch for GNU GRUB uses world-readable permissions for grub
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.
OSV
CVE-2013-4577: A certain Debian patch for GNU GRUB uses world-readable permissions for grub
osv·2014-05-12·CVSS 2.1
CVE-2013-4577 [LOW] CVE-2013-4577: A certain Debian patch for GNU GRUB uses world-readable permissions for grub
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.
Debian
CVE-2013-4577: grub2 - A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg...
vendor_debian·2013·CVSS 2.1
CVE-2013-4577 [LOW] CVE-2013-4577: grub2 - A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg...
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.
Scope: local
bookworm: resolved (fixed in 2.00-20)
bullseye: resolved (fixed in 2.00-20)
forky: resolved (fixed in 2.00-20)
sid: resolved (fixed in 2.00-20)
trixie: resolved (fixed in 2.00-20)
Red Hat
CVE-2013-4577: A certain Debian patch for GNU GRUB uses world-readable permissions for grub
vendor_redhat·CVSS 2.1
CVE-2013-4577 [LOW] CVE-2013-4577: A certain Debian patch for GNU GRUB uses world-readable permissions for grub
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.
Statement: Not vulnerable. This issue did not affect the grub or grub2 packages shipped in Red Hat products.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/oss-sec/2013/q4/291http://seclists.org/oss-sec/2013/q4/292http://www.openwall.com/lists/oss-security/2024/01/15/3https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=632598http://seclists.org/oss-sec/2013/q4/291http://seclists.org/oss-sec/2013/q4/292http://www.openwall.com/lists/oss-security/2024/01/15/3https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=632598
2014-05-12
Published