V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2019-14865
DEB
Medium

A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example b…

CVSS
5.9
Medium
EPSS
0.00
p24
Published
2019-01-01
Updated
2019-01-01
Description

A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots.

Tags · CWE
CWE-267
CAPEC-58
CAPEC-634
CAPEC-637
CAPEC-643
CAPEC-648
Affected products
Grub2Grub2Grub2Grub2Grub2Grub2Grub2Grub2
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: R
Required (R)
Scope
S: C
Changed (C)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.003 · p24
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-648 · CWE-267
└ via CAPEC-637 · CWE-267
└ via CAPEC-634 · CWE-267
└ via CAPEC-634 · CWE-267
└ via CAPEC-643 · CWE-267
└ via CAPEC-648 · CWE-267
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2Tracked
grub2*Tracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities