Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-15706 – GRUB2 contains a race condition in grub_script_function_create() leading

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15706

Reference (s):

  • https://security.netapp.com/advisory/ntap-20200731-0008/
  • https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.html
  • URL: https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.html
  • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011
  • URL: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-9235 - Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos

2021-current

CVE-2020-0828 - A remote code execution vulnerability exists in the way that the ChakraCo

2021-current

CVE-2020-14827 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Ser