Loading
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.
Use CWE-264, Gnu vendor hub and Grub product page to widen CVE-2013-4577 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-4949 for nearby disclosures in the same product family.