openSUSE-SU-2019:2628-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:2628-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2019:2628-1
Related
Published
2019-12-03T14:50:29Z
Modified
2019-12-03T14:50:29Z
Summary
Security update for calamares
Details

This update for calamares fixes the following issues:

  • Launch with 'pkexec calamares' in openSUSE Tumbleweed, but launch with 'xdg-su -c calamares' in openSUSE Leap 15.

Update to Calamares 3.2.15:

  • 'displaymanager' module now treats 'sysconfig' as a regular entry in the 'displaymanagers' list, and the 'sysconfigSetup' key is used as a shorthand to force only that entry in the list.
  • 'machineid' module has been re-written in C++ and extended with a new configuration key to generate urandom pool data.
  • 'unpackfs' now supports a special 'sourcefs' value of file for copying single files (optionally with renaming) or directory trees to the target system.
  • 'unpackfs' now support an 'exclude' and 'excludeFile' setting for excluding particular files or patters from unpacking.

Update to Calamares 3.2.14: - 'locale' module no longer recognizes the legacy GeoIP configuration. This has been deprecated since Calamares 3.2.8 and is now removed. - 'packagechooser' module can now be custom-labeled in the overall progress (left-hand column). - 'displaymanager' module now recognizes KDE Plasma 5.17. - 'displaymanager' module now can handle Wayland sessions and can detect sessions from their .desktop files. - 'unpackfs' now has special handling for sourcefs setting “file”.

Update to Calamares 3.2.13.

More about upstream changes:

https://calamares.io/calamares-3.2.13-is-out/ and https://calamares.io/calamares-3.2.12-is-out/

Update to Calamares 3.2.11:

  • Fix race condition in modules/luksbootkeyfile/main.py (boo#1140256, CVE-2019-13178)
  • more about upstream changes in 3.2 versions can be found in https://calamares.io/ and https://github.com/calamares/calamares/releases
References

Affected packages

openSUSE:Leap 15.0 / calamares

Package

Name
calamares
Purl
pkg:rpm/opensuse/calamares&distro=openSUSE%20Leap%2015.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.15-lp151.4.3.3

Ecosystem specific

{
    "binaries": [
        {
            "calamares": "3.2.15-lp151.4.3.3",
            "calamares-branding-upstream": "3.2.15-lp151.4.3.3",
            "calamares-webview": "3.2.15-lp151.4.3.3"
        }
    ]
}

openSUSE:Leap 15.1 / calamares

Package

Name
calamares
Purl
pkg:rpm/opensuse/calamares&distro=openSUSE%20Leap%2015.1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.2.15-lp151.4.3.3

Ecosystem specific

{
    "binaries": [
        {
            "calamares": "3.2.15-lp151.4.3.3",
            "calamares-branding-upstream": "3.2.15-lp151.4.3.3",
            "calamares-webview": "3.2.15-lp151.4.3.3"
        }
    ]
}