CVE

Id
64524  
CVE No.
CVE-2013-4577  
Status
Candidate  
Description
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.  
Phase
Assigned (20130612)  
Votes
None (candidate not yet proposed)  
Comments