Back to search
CVE-2019-13179
Published: Jul 2, 2019
Modified: Aug 4, 2024
PUBLISHED
Description
Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/calamares/calamares/issues/1191
x_refsource_MISC
https://bugzilla.redhat.com/show_bug.cgi?id=1726542
x_refsource_MISC
https://calamares.io/calamares-3.2.11-is-out/
x_refsource_CONFIRM
https://calamares.io/calamares-cve-2019/
x_refsource_CONFIRM
FEDORA-2019-50ee491d76
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-e61a85c2bb
vendor-advisory
x_refsource_FEDORA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now