CVE-2019-13179
Summary
| CVE | CVE-2019-13179 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-02 23:15:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug #1835095 “Lubuntu initrd images leaking cryptographic secret...” : Bugs : calamares package : Ubuntu | MISC | bugs.launchpad.net | Exploit, Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 29 Update: calamares-3.2.11-1.fc29 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 30 Update: calamares-3.2.11-1.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Calamares Initramfs Weakness – Calamares – The universal installer framework | CONFIRM | calamares.io | Vendor Advisory |
| 1726542 – (CVE-2019-13179) CVE-2019-13179 calamares: incorrect permission leads to disclosure of decryption keys for LUKS container | MISC | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 29 Update: calamares-3.2.11-1.fc29 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Bug #1835096 “Unprivileged user can access LUKS keyfile” : Bugs : initramfs-tools package : Ubuntu | MISC | bugs.launchpad.net | Third Party Advisory |
| Unsafe generation of initramfs during FDE · Issue #1191 · calamares/calamares · GitHub | MISC | github.com | Exploit, Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 30 Update: calamares-3.2.11-1.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Calamares 3.2.11 released - Calamares | CONFIRM | calamares.io | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.