CVE-2013-4577
Description
From CVE.org
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.
Statement
Not vulnerable. This issue did not affect the grub or grub2 packages shipped in Red Hat products.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.