Описание
Security update for calamares
This update for calamares fixes the following issues:
- Launch with 'pkexec calamares' in openSUSE Tumbleweed, but launch with 'xdg-su -c calamares' in openSUSE Leap 15.
Update to Calamares 3.2.15:
- 'displaymanager' module now treats 'sysconfig' as a regular entry in the 'displaymanagers' list, and the 'sysconfigSetup' key is used as a shorthand to force only that entry in the list.
- 'machineid' module has been re-written in C++ and extended with a new configuration key to generate urandom pool data.
- 'unpackfs' now supports a special 'sourcefs' value of file for copying single files (optionally with renaming) or directory trees to the target system.
- 'unpackfs' now support an 'exclude' and 'excludeFile' setting for excluding particular files or patters from unpacking.
Update to Calamares 3.2.14:
- 'locale' module no longer recognizes the legacy GeoIP configuration. This has been deprecated since Calamares 3.2.8 and is now removed.
- 'packagechooser' module can now be custom-labeled in the overall progress (left-hand column).
- 'displaymanager' module now recognizes KDE Plasma 5.17.
- 'displaymanager' module now can handle Wayland sessions and can detect sessions from their .desktop files.
- 'unpackfs' now has special handling for sourcefs setting “file”.
Update to Calamares 3.2.13.
More about upstream changes:
https://calamares.io/calamares-3.2.13-is-out/ and https://calamares.io/calamares-3.2.12-is-out/
Update to Calamares 3.2.11:
- Fix race condition in modules/luksbootkeyfile/main.py (boo#1140256, CVE-2019-13178)
- more about upstream changes in 3.2 versions can be found in https://calamares.io/ and https://github.com/calamares/calamares/releases
Список пакетов
openSUSE Leap 15.0
calamares-3.2.15-lp151.4.3.3
calamares-branding-upstream-3.2.15-lp151.4.3.3
calamares-webview-3.2.15-lp151.4.3.3
openSUSE Leap 15.1
calamares-3.2.15-lp151.4.3.3
calamares-branding-upstream-3.2.15-lp151.4.3.3
calamares-webview-3.2.15-lp151.4.3.3
Ссылки
- E-Mail link for openSUSE-SU-2019:2628-1
- SUSE Security Ratings
- SUSE Bug 1140256
- SUSE Bug 1152377
- SUSE CVE CVE-2019-13178 page
Описание
modules/luksbootkeyfile/main.py in Calamares versions 3.1 through 3.2.10 has a race condition between the time when the LUKS encryption keyfile is created and when secure permissions are set.
Затронутые продукты
openSUSE Leap 15.0:calamares-3.2.15-lp151.4.3.3
openSUSE Leap 15.0:calamares-branding-upstream-3.2.15-lp151.4.3.3
openSUSE Leap 15.0:calamares-webview-3.2.15-lp151.4.3.3
openSUSE Leap 15.1:calamares-3.2.15-lp151.4.3.3
Ссылки
- CVE-2019-13178
- SUSE Bug 1140256