CVE-2013-4577

Description

From CVE.org

A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.

Statement

Not vulnerable. This issue did not affect the grub or grub2 packages shipped in Red Hat products.

Frequently Asked Questions

Want to get errata notifications? Sign up here.