{"affected":[{"ecosystem_specific":{"binaries":[{"grub2":"2.02~beta2-73.3","grub2-i386-pc":"2.02~beta2-73.3","grub2-snapper-plugin":"2.02~beta2-73.3","grub2-x86_64-efi":"2.02~beta2-73.3","grub2-x86_64-xen":"2.02~beta2-73.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP1","name":"grub2","purl":"pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.02~beta2-73.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"grub2":"2.02~beta2-73.3","grub2-i386-pc":"2.02~beta2-73.3","grub2-powerpc-ieee1275":"2.02~beta2-73.3","grub2-s390x-emu":"2.02~beta2-73.3","grub2-snapper-plugin":"2.02~beta2-73.3","grub2-x86_64-efi":"2.02~beta2-73.3","grub2-x86_64-xen":"2.02~beta2-73.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP1","name":"grub2","purl":"pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.02~beta2-73.3"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"grub2":"2.02~beta2-73.3","grub2-i386-pc":"2.02~beta2-73.3","grub2-powerpc-ieee1275":"2.02~beta2-73.3","grub2-s390x-emu":"2.02~beta2-73.3","grub2-snapper-plugin":"2.02~beta2-73.3","grub2-x86_64-efi":"2.02~beta2-73.3","grub2-x86_64-xen":"2.02~beta2-73.3"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP1","name":"grub2","purl":"pkg:rpm/suse/grub2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.02~beta2-73.3"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\n\n- Fix buffer overflows when reading username and password. (bsc#956631, CVE-2015-8370)\n- Check MS-DOS header to find PE file header. (bsc#954126)\n- Use dirname for copying Xen kernel and initrd to esp. (bsc#955493)\n- Fix reading password by grub2-mkpasswd-pbdk2 without controlling tty. (bsc#954519)\n- Add luks, gcry_rijndael and gcry_sha1 to signed EFI image to support LUKS partition\n  in default setup. (bsc#917427, bsc#955609)\n- Expand list of grub.cfg search path in PV Xen guests for systems installed on btrfs\n  snapshots. (bsc#946148, bsc#952539)\n","id":"SUSE-SU-2015:2387-1","modified":"2015-12-29T08:05:08Z","published":"2015-12-29T08:05:08Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2015/suse-su-20152387-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/774666"},{"type":"REPORT","url":"https://bugzilla.suse.com/917427"},{"type":"REPORT","url":"https://bugzilla.suse.com/946148"},{"type":"REPORT","url":"https://bugzilla.suse.com/952539"},{"type":"REPORT","url":"https://bugzilla.suse.com/954126"},{"type":"REPORT","url":"https://bugzilla.suse.com/954519"},{"type":"REPORT","url":"https://bugzilla.suse.com/955493"},{"type":"REPORT","url":"https://bugzilla.suse.com/955609"},{"type":"REPORT","url":"https://bugzilla.suse.com/956631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-8370"}],"related":["CVE-2015-8370"],"summary":"Security update for grub2","upstream":["CVE-2015-8370"]}