CVE-2020-13845

NameCVE-2020-13845
DescriptionSylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs965040

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
singularity-container (PTS)sid4.1.5+ds3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
singularity-containersourceexperimental3.9.4+ds2-1
singularity-containersource(unstable)3.9.5+ds1-2965040

Notes

https://github.com/hpcng/singularity/security/advisories/GHSA-pmfr-63c2-jr5c

Search for package or bug name: Reporting problems