VDB
BDU%3A2020-03971
BDU%3A2020-03971
PUBLISHED
CVSS 4.400000095367432 MEDIUM
Уязвимость реализации функции grub_script_function_create() загрузчика операционных систем Grub2, позволяющая нарушителю получить доступ к конфиденциальным данным, оказать влияние на целостность данных, а также вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
4.400000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp, Red Hat Inc., Canonical Ltd., Сообщество свободного программного обеспечения, ООО «РусБИТех-Астра», Novell Inc., Erich Boleyn, ООО «Ред Софт», ФССП России, АО «Концерн ВНИИНС» | Windows 8.1, Windows Server 2012, Windows Server 2012 R2, Windows RT 8.1, Windows 10, Red Hat Enterprise Linux, Ubuntu, Windows 10 1607, Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Debian GNU/Linux, Windows 10 1709, Windows 10 1803, Windows 10 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Astra Linux Special Edition (запись в едином реестре российских программ №369), Windows 10 1903, Windows Server 1903 (Server Core Installation), OpenSUSE Leap, Windows 10 1909, Windows Server 1909 (Server Core Installation), Windows 10 2004, Windows Server 2004 (Server Core Installation), Grub2, РЕД ОС (запись в едином реестре российских программ №3751), ОС ТД АИС ФССП России, Windows Server 2012 (Server Core installation), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Aug 19, 2020 CVE Published
- Nov 21, 2023 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
References
- https://lists.gnu.org/archive/html/grub-devel/2020-07/msg00034.html url
- https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00017.html url
- https://nvd.nist.gov/vuln/detail/CVE-2020-15706 url
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV200011 url
- https://ubuntu.com/security/notices/USN-4432-1 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20200807SE16MD url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20210611SE16 url
- https://redos.red-soft.ru/support/secure/uyazvimosti/mnozhestvennye-uyazvimosti-grub-/?sphrase_id=63279 url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url
- https://lists.opensuse.org/opensuse-security-announce/2020-08/msg00016.html advisory
- https://access.redhat.com/security/cve/cve-2020-15706 advisory
- https://security-tracker.debian.org/tracker/CVE-2020-15706 advisory
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20210730SE16 advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://goslinux.fssp.gov.ru/2726972/ advisory