Incorrect default permissions in Calamares - CVE-2019-13179
Published: December 5, 2019
Calamares
Detailed vulnerability description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to incorrect default permissions for files that are copied from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image. A local user can decryption keys for LUKS containers created with Full Disk Encryption.
How to mitigate CVE-2019-13179
Sources
- https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/1835095
- https://bugs.launchpad.net/ubuntu/+source/initramfs-tools/+bug/1835096
- https://bugzilla.redhat.com/show_bug.cgi?id=1726542
- https://calamares.io/calamares-3.2.11-is-out/
- https://calamares.io/calamares-cve-2019/
- https://github.com/calamares/calamares/issues/1191
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q57BOTBA2J5U4GVKUP7N2PD5H7B3BVUU/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R2ZDQRGBGRVRW5LPJWKUNS3M66LZ3KYC/