Search CVE reports


Toggle filters

11 – 20 of 20 results


CVE-2020-25040

Medium priority
Needs evaluation

Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.

1 affected package

singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
singularity-container Needs evaluation Not in release Not in release Needs evaluation
Show less packages

CVE-2020-25039

Medium priority
Needs evaluation

Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.

1 affected package

singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
singularity-container Needs evaluation Not in release Not in release Needs evaluation
Show less packages

CVE-2020-13847

Medium priority
Needs evaluation

Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file.

1 affected package

singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
singularity-container Needs evaluation Not in release Not in release Needs evaluation
Show less packages

CVE-2020-13846

Low priority
Needs evaluation

Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.

1 affected package

singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
singularity-container Needs evaluation Not in release Not in release Needs evaluation
Show less packages

CVE-2020-13845

Medium priority
Needs evaluation

Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object...

1 affected package

singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
singularity-container Needs evaluation Not in release Not in release Needs evaluation
Show less packages

CVE-2020-8945

Medium priority
Vulnerable

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.

2 affected packages

golang-github-proglottis-gpgme, singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-proglottis-gpgme Not affected Not affected Vulnerable Not in release
singularity-container Needs evaluation Not in release Not in release Needs evaluation
Show less packages

CVE-2019-19724

Medium priority
Not affected

Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against...

1 affected package

singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
singularity-container Not affected
Show less packages

CVE-2019-10214

Medium priority
Needs evaluation

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry...

2 affected packages

golang-github-containers-image, singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-github-containers-image Needs evaluation Needs evaluation Needs evaluation Not in release
singularity-container Needs evaluation Not in release Not in release Needs evaluation
Show less packages

CVE-2018-19295

High priority

Some fixes available 1 of 2

Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.

1 affected package

singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
singularity-container Not in release Not in release Fixed
Show less packages

CVE-2018-12021

Medium priority

Some fixes available 1 of 2

Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific...

1 affected package

singularity-container

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
singularity-container Not in release Not in release Fixed
Show less packages