First published: Fri May 04 2012(Updated: )
The bootloader configuration module (pyanaconda/bootloader.py) in Anaconda uses 755 permissions for /etc/grub.d, which allows local users to obtain password hashes and conduct brute force password guessing attacks.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/grub2-1.99 | <13. | 13. |
Fedoraproject Anaconda |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.