CVE-2019-13179

EUVD-2019-4703
Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Affected Products (NVD)
VendorProductVersion
calamarescalamares
𝑥
≤ 3.2.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
calamares
bookworm
3.2.61-1
fixed
bullseye
3.2.36-1
fixed
buster
ignored
sid
3.3.9-1
fixed
trixie
3.3.9-1
fixed
calamares-settings-debian
bookworm
12.0.9-1+deb12u1
fixed
bullseye
11.0.5-2
fixed
buster
ignored
sid
13.0.11-1
fixed
trixie
13.0.11-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
calamares
bionic
needed
cosmic
ignored
disco
ignored
eoan
ignored
focal
needed
groovy
ignored
hirsute
ignored
impish
ignored
jammy
needed
kinetic
ignored
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
dne
xenial
dne