{"id":"SUSE-SU-2015:2385-1","summary":"Security update for grub2","details":"This update for grub2 provides the following fixes:\n\nA security issues with a bufferoverflow when reading username and password was fixed (bsc#956631, CVE-2015-8370)\n\nAlso following bugs were fixed:\n- Fix buffer overflows when reading username and password. (bsc#956631, CVE-2015-8370)\n- Expand list of grub.cfg search path in PV Xen guests for systems installed\n  on btrfs snapshots. (bsc#946148, bsc#952539)\n- Add grub.xen config searching path on boot partition. (bsc#884828)\n- Add linux16 and initrd16 to grub.xen. (bsc#884830)\n","modified":"2026-02-04T02:41:39.525350Z","published":"2015-12-29T08:04:56Z","related":["CVE-2015-8370"],"upstream":["CVE-2015-8370"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20152385-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/884828"},{"type":"REPORT","url":"https://bugzilla.suse.com/884830"},{"type":"REPORT","url":"https://bugzilla.suse.com/946148"},{"type":"REPORT","url":"https://bugzilla.suse.com/952539"},{"type":"REPORT","url":"https://bugzilla.suse.com/954592"},{"type":"REPORT","url":"https://bugzilla.suse.com/956631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-8370"}],"affected":[{"package":{"name":"grub2","ecosystem":"SUSE:Linux Enterprise Desktop 11 SP4","purl":"pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.00-0.54.2"}]}],"ecosystem_specific":{"binaries":[{"grub2-x86_64-efi":"2.00-0.54.2","grub2-x86_64-xen":"2.00-0.54.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:2385-1.json"}},{"package":{"name":"grub2","ecosystem":"SUSE:Linux Enterprise Server 11 SP4","purl":"pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.00-0.54.2"}]}],"ecosystem_specific":{"binaries":[{"grub2-x86_64-efi":"2.00-0.54.2","grub2-x86_64-xen":"2.00-0.54.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:2385-1.json"}},{"package":{"name":"grub2","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","purl":"pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.00-0.54.2"}]}],"ecosystem_specific":{"binaries":[{"grub2-x86_64-xen":"2.00-0.54.2","grub2-x86_64-efi":"2.00-0.54.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2015:2385-1.json"}}],"schema_version":"1.7.3"}