CVE-2020-25039: High severity singularity vulnerability
Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25039?
CVE-2020-25039 is a vulnerability in Sylabs Singularity versions 3.2.0 through 3.6.2 that allows for insecure permissions on temporary directories used in fakeroot or user namespace container execution.
What software is affected by CVE-2020-25039?
Sylabs Singularity versions 3.2.0 through 3.6.2 are affected by CVE-2020-25039.
How severe is CVE-2020-25039?
CVE-2020-25039 has a severity rating of 8.1 (high).
How can I fix CVE-2020-25039?
To fix CVE-2020-25039, update Sylabs Singularity to a version higher than 3.6.2.
Where can I find more information about CVE-2020-25039?
You can find more information about CVE-2020-25039 in the references provided: http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00070.html, http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00088.html, https://github.com/hpcng/singularity/security/advisories/GHSA-w6v2-qchm-grj7