[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2019-13179 -- calamares-settings-debian, calamares

ID: oval:org.secpod.oval:def:2004745Date: (C)2020-10-22   (M)2023-11-13
Class: VULNERABILITYFamily: unix




Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.

Platform:
Debian 10.x
Product:
calamares-settings-debian
calamares
Reference:
CVE-2019-13179
CVE    1
CVE-2019-13179
CPE    3
cpe:/a:debian:calamares-settings-debian
cpe:/o:debian:debian_linux:10.x
cpe:/a:calamares:calamares

© SecPod Technologies