CVE-2018-19295: Input Validation
Published Dec 17, 2018
·Updated
Sylabs Singularity 2.4 to 2.6 allows local users to conduct Improper Input Validation attacks.
Affected Software
2 affected componentsFixes available
go/github.com/sylabs/singularity>=2.4.0<2.6.1
2.6.1
Sylabs Singularity>=2.4<=2.6.0
Event History
Dec 17, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
May 14, 2022
Advisory Published
01:39 AM
Frequently Asked Questions
1
What is CVE-2018-19295?
CVE-2018-19295 is a vulnerability in Sylabs Singularity 2.4 to 2.6 that allows local users to conduct Improper Input Validation attacks.
2
How can local users exploit CVE-2018-19295?
Local users can exploit CVE-2018-19295 by conducting Improper Input Validation attacks.
3
What is the severity of CVE-2018-19295?
The severity of CVE-2018-19295 is high with a CVSS score of 7.8.
4
Which software versions are affected by CVE-2018-19295?
Sylabs Singularity versions 2.4 to 2.6 are affected by CVE-2018-19295.
5
How can I fix CVE-2018-19295?
To fix CVE-2018-19295, update to version 2.6.1 of Sylabs Singularity.