UBUNTU-CVE-2019-13179

Source
https://ubuntu.com/security/CVE-2019-13179
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-13179.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2019-13179
Upstream
Published
2019-07-02T23:15:00Z
Modified
2025-10-24T04:47:42Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.

References

Affected packages

Ubuntu:18.04:LTS / calamares

Package

Name
calamares
Purl
pkg:deb/ubuntu/calamares@3.1.12-1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.1.7-1
3.1.7-2
3.1.8-0ubuntu1
3.1.8-1
3.1.9-1
3.1.10-1
3.1.12-0ubuntu1
3.1.12-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.1.12-1",
            "binary_name": "calamares"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-13179.json"

Ubuntu:20.04:LTS / calamares

Package

Name
calamares
Purl
pkg:deb/ubuntu/calamares@3.2.20-0ubuntu1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.2.14-0ubuntu2
3.2.14-0ubuntu3
3.2.17.1-0ubuntu1
3.2.17.1-0ubuntu2
3.2.17.1-0ubuntu4
3.2.17.1-0ubuntu5
3.2.18-0ubuntu1
3.2.19-0ubuntu1
3.2.19.1-0ubuntu1
3.2.20-0ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.2.20-0ubuntu1",
            "binary_name": "calamares"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-13179.json"

Ubuntu:22.04:LTS / calamares

Package

Name
calamares
Purl
pkg:deb/ubuntu/calamares@3.2.61-0ubuntu0.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.2.41.1-0ubuntu1
3.2.41.1-0ubuntu2
3.2.41.1-0ubuntu3
3.2.41.1-0ubuntu4
3.2.60-0ubuntu0.1
3.2.61-0ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.2.61-0ubuntu0.1",
            "binary_name": "calamares"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-13179.json"