GLSA-202104-05 : GRUB: Multiple vulnerabilities

high Nessus Plugin ID 149217

Synopsis

The remote Gentoo host is missing one or more security-related patches.

Description

The remote host is affected by the vulnerability described in GLSA-202104-05 (GRUB: Multiple vulnerabilities)

Multiple vulnerabilities have been discovered in GRUB. Please review the CVE identifiers referenced below for details.
Impact :

Please review the referenced CVE identifiers for details.
Workaround :

There is no known workaround at this time.

Solution

All GRUB users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=sys-devel/grub-2.06_rc1' After upgrading, make sure to run the grub-install command with options appropriate for your system. See the GRUB Quick Start guide in the references below for examples. Your system will be vulnerable until this action is performed.

See Also

https://wiki.gentoo.org/wiki/GRUB2_Quick_Start

https://security.gentoo.org/glsa/202104-05

Plugin Details

Severity: High

ID: 149217

File Name: gentoo_GLSA-202104-05.nasl

Version: 1.4

Type: local

Published: 5/3/2021

Updated: 12/7/2022

Risk Information

VPR

Risk Factor: High

Score: 8.1

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: E:U/RL:OF/RC:C

CVSS v3

Risk Factor: High

Base Score: 8.2

Temporal Score: 7.1

Vector: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:gentoo:linux:grub, cpe:/o:gentoo:linux

Required KB Items: Host/local_checks_enabled, Host/Gentoo/release, Host/Gentoo/qpkg-list

Exploit Ease: No known exploits are available

Patch Publication Date: 4/30/2021

Vulnerability Publication Date: 7/29/2020

Reference Information

CVE: CVE-2020-10713, CVE-2020-14308, CVE-2020-14309, CVE-2020-14310, CVE-2020-14311, CVE-2020-14372, CVE-2020-15705, CVE-2020-15706, CVE-2020-15707, CVE-2020-25632, CVE-2020-25647, CVE-2020-27749, CVE-2020-27779, CVE-2021-20225, CVE-2021-20233

GLSA: 202104-05

CEA-ID: CEA-2020-0061