c78952
From 9961e63642244617b697d93bbc49379e23b6839d Mon Sep 17 00:00:00 2001
bf8e18
From: Hector Marco-Gisbert <hecmargi@upv.es>
bf8e18
Date: Fri, 13 Nov 2015 16:21:09 +0100
31cddd
Subject: [PATCH] Fix security issue when reading username and password
bf8e18
bf8e18
  This patch fixes two integer underflows at:
bf8e18
    * grub-core/lib/crypto.c
bf8e18
    * grub-core/normal/auth.c
bf8e18
bf8e18
Resolves: CVE-2015-8370
bf8e18
bf8e18
Signed-off-by: Hector Marco-Gisbert <hecmargi@upv.es>
bf8e18
Signed-off-by: Ismael Ripoll-Ripoll <iripoll@disca.upv.es>
bf8e18
---
bf8e18
 grub-core/lib/crypto.c  | 2 +-
bf8e18
 grub-core/normal/auth.c | 2 +-
bf8e18
 2 files changed, 2 insertions(+), 2 deletions(-)
bf8e18
bf8e18
diff --git a/grub-core/lib/crypto.c b/grub-core/lib/crypto.c
ec4acb
index ca334d5a40e..e6c78d16d39 100644
bf8e18
--- a/grub-core/lib/crypto.c
bf8e18
+++ b/grub-core/lib/crypto.c
bf8e18
@@ -468,7 +468,7 @@ grub_password_get (char buf[], unsigned buf_size)
bf8e18
 	  break;
bf8e18
 	}
bf8e18
 
bf8e18
-      if (key == '\b')
bf8e18
+      if (key == '\b' && cur_len)
bf8e18
 	{
b9efc5
 	  if (cur_len)
b9efc5
 	    cur_len--;
bf8e18
diff --git a/grub-core/normal/auth.c b/grub-core/normal/auth.c
ec4acb
index 6be678c0de1..c35ce972473 100644
bf8e18
--- a/grub-core/normal/auth.c
bf8e18
+++ b/grub-core/normal/auth.c
bf8e18
@@ -172,7 +172,7 @@ grub_username_get (char buf[], unsigned buf_size)
bf8e18
 	  break;
bf8e18
 	}
bf8e18
 
bbc6a8
-      if (key == GRUB_TERM_BACKSPACE)
bbc6a8
+      if (key == GRUB_TERM_BACKSPACE && cur_len)
bf8e18
 	{
b9efc5
 	  if (cur_len)
b9efc5
 	    {