Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-13179

Опубликовано: 02 июл. 2019
Источник: debian

Описание

Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
calamaresfixed3.2.11-1package
calamaresignoredbusterpackage
calamares-settings-debianfixed10.0.23-1package
calamares-settings-debianfixed10.0.20-1+deb10u1busterpackage

Примечания

  • https://github.com/calamares/calamares/issues/1191

  • https://github.com/calamares/calamares/commit/003096698627a527b589c0c929dda4d58f23fd93

  • The issue itself can be adressed as well via calamares-settings-debian and

  • placing a more restrictive umask override in /etc/initramfs-tools/conf.d

  • directory.

  • https://github.com/calamares/calamares/commit/43eb664e7d44d963bb7b82d03215d84b47100ba0

  • Fixed by: https://github.com/calamares/calamares/commit/c9b675cbc64ac5aab35ddd86a64311abd50f7720

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.

CVSS3: 7.5
nvd
больше 6 лет назад

Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.

CVSS3: 7.5
github
больше 3 лет назад

Calamares through 3.2.4 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.