Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-15705 – GRUB2 fails to validate kernel signature when booted directly without shi

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15705

Reference (s):

  • https://security.netapp.com/advisory/ntap-20200731-0008/
  • https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.html
  • URL: https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.html
  • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011
  • URL: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-4742 - Cross-site scripting (XSS) vulnerability in system/class_link.php in the

2021-current

CVE-2014-9837 - coders/pnm.c in ImageMagick 6.9.0-1 Beta and earlier allows remote attack

2021-current

CVE-2020-10446 - The way URIs are handled in admin/header.php in Chadha PHPKB Standard Mul