First published: Wed Sep 16 2020(Updated: )
Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sylabs Singularity | >=3.2.0<=3.6.2 | |
openSUSE | =15.1 | |
openSUSE | =15.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25039 is a vulnerability in Sylabs Singularity versions 3.2.0 through 3.6.2 that allows for insecure permissions on temporary directories used in fakeroot or user namespace container execution.
Sylabs Singularity versions 3.2.0 through 3.6.2 are affected by CVE-2020-25039.
CVE-2020-25039 has a severity rating of 8.1 (high).
To fix CVE-2020-25039, update Sylabs Singularity to a version higher than 3.6.2.
You can find more information about CVE-2020-25039 in the references provided: http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00070.html, http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00088.html, https://github.com/hpcng/singularity/security/advisories/GHSA-w6v2-qchm-grj7