6.8
CVSSv2

CVE-2019-13178

Published: 02/07/2019 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

modules/luksbootkeyfile/main.py in Calamares versions 3.1 up to and including 3.2.10 has a race condition between the time when the LUKS encryption keyfile is created and when secure permissions are set.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

calamares calamares

Vendor Advisories

Debian Bug report logs - #931391 calamares: CVE-2019-13178 Package: src:calamares; Maintainer for src:calamares is Jonathan Carter <jcc@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 3 Jul 2019 19:39:02 UTC Severity: important Tags: security, upstream Found in versions calamares/324 ...