{"id":"openSUSE-SU-2019:2628-1","summary":"Security update for calamares","details":"This update for calamares fixes the following issues:\n\n- Launch with 'pkexec calamares' in openSUSE Tumbleweed, but\n  launch with 'xdg-su -c calamares' in openSUSE Leap 15.\n\nUpdate to Calamares 3.2.15:\n\n- 'displaymanager' module now treats 'sysconfig' as a regular \n  entry in the 'displaymanagers' list, and the 'sysconfigSetup' \n  key is used as a shorthand to force only that entry in the \n  list.\n- 'machineid' module has been re-written in C++ and extended \n  with a new configuration key to generate urandom pool data.\n- 'unpackfs' now supports a special 'sourcefs' value of file \n  for copying single files (optionally with renaming) or \n  directory trees to the target system.\n- 'unpackfs' now support an 'exclude' and 'excludeFile' setting \n  for excluding particular files or patters from unpacking.\n\nUpdate to Calamares 3.2.14:\n- 'locale' module no longer recognizes the legacy GeoIP \n  configuration. This has been deprecated since Calamares 3.2.8 \n  and is now removed.\n- 'packagechooser' module can now be custom-labeled in the overall\n  progress (left-hand column).\n- 'displaymanager' module now recognizes KDE Plasma 5.17.\n- 'displaymanager' module now can handle Wayland sessions and can\n  detect sessions from their .desktop files.\n- 'unpackfs' now has special handling for sourcefs setting “file”. \n\nUpdate to Calamares 3.2.13.\n\nMore about upstream changes:\n\n  https://calamares.io/calamares-3.2.13-is-out/ and\n  https://calamares.io/calamares-3.2.12-is-out/\n\nUpdate to Calamares 3.2.11:\n\n- Fix race condition in modules/luksbootkeyfile/main.py \n  (boo#1140256, CVE-2019-13178)\n- more about upstream changes in 3.2 versions can be found in \n  https://calamares.io/ and \n  https://github.com/calamares/calamares/releases\n\n","modified":"2026-02-04T04:18:07.750460Z","published":"2019-12-03T14:50:29Z","related":["CVE-2019-13178"],"upstream":["CVE-2019-13178"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/F37KTDMSUVC5W6DQSVTR4KZ7P2V4DLGL/#F37KTDMSUVC5W6DQSVTR4KZ7P2V4DLGL"},{"type":"REPORT","url":"https://bugzilla.suse.com/1140256"},{"type":"REPORT","url":"https://bugzilla.suse.com/1152377"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13178"}],"affected":[{"package":{"name":"calamares","ecosystem":"openSUSE:Leap 15.0","purl":"pkg:rpm/opensuse/calamares&distro=openSUSE%20Leap%2015.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.15-lp151.4.3.3"}]}],"ecosystem_specific":{"binaries":[{"calamares-branding-upstream":"3.2.15-lp151.4.3.3","calamares-webview":"3.2.15-lp151.4.3.3","calamares":"3.2.15-lp151.4.3.3"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:2628-1.json"}},{"package":{"name":"calamares","ecosystem":"openSUSE:Leap 15.1","purl":"pkg:rpm/opensuse/calamares&distro=openSUSE%20Leap%2015.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.15-lp151.4.3.3"}]}],"ecosystem_specific":{"binaries":[{"calamares":"3.2.15-lp151.4.3.3","calamares-branding-upstream":"3.2.15-lp151.4.3.3","calamares-webview":"3.2.15-lp151.4.3.3"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2019:2628-1.json"}}],"schema_version":"1.7.3"}