Password leak from encrypted partitions in the Ubuntu Server installer log

Canonical released installer patch release Subiquity 20.05.2, which is the default for installing Ubuntu Server since the 18.04 release in Live mode. The new release resolves a security issue (CVE-2020-11932), caused by logging the password set by the user to access the encrypted LUKS partition created during installation. Updates ISO images that fix the vulnerability have not yet been released, but the new version of Subiquity with the fix is available in the Snap Store directory, from which the installer can be updated while booting in Live mode, before the system installation begins.

The password for the encrypted partition is stored in plaintext in the files autoinstall-user-data, curtin-install-cfg.yaml, curtin-install.log, installer-journal.txt, and subiquity-curtin-install.conf, saved after installation in the /var/log/installer directory. In configurations where the /var partition is not encrypted, in case the system falls into the wrong hands, the passwords for the encrypted partitions can be extracted from these files, negating the purpose of encryption.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster