Search CVE reports
11 – 20 of 20 results
Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.
1 affected package
singularity-container
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| singularity-container | Needs evaluation | Not in release | Not in release | Needs evaluation |
Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
1 affected package
singularity-container
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| singularity-container | Needs evaluation | Not in release | Not in release | Needs evaluation |
Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file.
1 affected package
singularity-container
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| singularity-container | Needs evaluation | Not in release | Not in release | Needs evaluation |
Sylabs Singularity 3.5.0 through 3.5.3 fails to report an error in a Status Code.
1 affected package
singularity-container
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| singularity-container | Needs evaluation | Not in release | Not in release | Needs evaluation |
Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object...
1 affected package
singularity-container
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| singularity-container | Needs evaluation | Not in release | Not in release | Needs evaluation |
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
2 affected packages
golang-github-proglottis-gpgme, singularity-container
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| golang-github-proglottis-gpgme | Not affected | Not affected | Vulnerable | Not in release |
| singularity-container | Needs evaluation | Not in release | Not in release | Needs evaluation |
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against...
1 affected package
singularity-container
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| singularity-container | — | — | — | Not affected |
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry...
2 affected packages
golang-github-containers-image, singularity-container
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| golang-github-containers-image | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
| singularity-container | Needs evaluation | Not in release | Not in release | Needs evaluation |
Some fixes available 1 of 2
Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.
1 affected package
singularity-container
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| singularity-container | — | Not in release | Not in release | Fixed |
Some fixes available 1 of 2
Singularity 2.3.0 through 2.5.1 is affected by an incorrect access control on systems supporting overlay file system. When using the overlay option, a malicious user may access sensitive information by exploiting a few specific...
1 affected package
singularity-container
| Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
|---|---|---|---|---|
| singularity-container | — | Not in release | Not in release | Fixed |