CVE-2012-2314

Anaconda - Unprotected Password Hash Exposure via /etc/grub.d Permissions

Title source: llm
STIX 2.1

Description

The bootloader configuration module (pyanaconda/bootloader.py) in Anaconda uses 755 permissions for /etc/grub.d, which allows local users to obtain password hashes and conduct brute force password guessing attacks.

Scores

EPSS 0.0040
EPSS Percentile 32.4%

Details

CWE
CWE-264
Status published
Products (1)
fedoraproject/anaconda
Published Jul 03, 2012
Tracked Since Feb 18, 2026