CVE-2020-25040

Name
CVE-2020-25040
Description
Sylabs Singularity through 3.6.2 has Insecure Permissions on temporary directories used in explicit and implicit container build operations, a different vulnerability than CVE-2020-25039.
NVD Severity
high
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Product https://medium.com/sylabs
Mitigation https://github.com/hpcng/singularity/security/advisories/GHSA-jv9c-w74q-6762
Third Party Advisory http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00070.html
Third Party Advisory http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00088.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:sylabs:singularity:*:*:*:*:*:*:*:* singularity >= None <= 3.6.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
singularity edge-community 3.6.3-r0 None fixed
singularity edge-community 3.6.0-r0 None possibly vulnerable
singularity edge-community 3.5.2-r0 None possibly vulnerable
singularity 3.22-community 3.6.3-r0 None fixed
singularity 3.22-community 3.6.0-r0 None possibly vulnerable
singularity 3.22-community 3.5.2-r0 None possibly vulnerable
singularity 3.21-community 3.6.3-r0 None fixed
singularity 3.20-community 3.6.3-r0 None fixed
singularity 3.19-community 3.6.3-r0 None fixed