Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.
References
Configurations
History
21 Nov 2024, 04:24
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/1835095 - Exploit, Issue Tracking, Third Party Advisory | |
References | () https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/1835096 - Third Party Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1726542 - Issue Tracking, Third Party Advisory | |
References | () https://calamares.io/calamares-3.2.11-is-out/ - Vendor Advisory | |
References | () https://calamares.io/calamares-cve-2019/ - Vendor Advisory | |
References | () https://github.com/calamares/calamares/issues/1191 - Exploit, Issue Tracking, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Q57BOTBA2J5U4GVKUP7N2PD5H7B3BVUU/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R2ZDQRGBGRVRW5LPJWKUNS3M66LZ3KYC/ - |
07 Nov 2023, 03:03
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2019-07-02 23:15
Updated : 2024-11-21 04:24
NVD link : CVE-2019-13179
Mitre link : CVE-2019-13179
CVE.ORG link : CVE-2019-13179
JSON object : View
Products Affected
calamares
- calamares
CWE
CWE-522
Insufficiently Protected Credentials