Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

openSUSE: 2020:1100-1 Important: Singularity Update for Security

opensuse
Calendar Grey September 18, 2020
Dist Opensuse Esm H88
A crucial enhancement for Singularity resolves concerns and bolsters safety. Upgrade now to reduce vulnerabilities.
An update that fixes three vulnerabilities is now available.

Description

This update for singularity fixes the following issues:

- New version 3.6.0. This version introduces a new signature format for

SIF images, and changes to the signing / verification code to address

the following security problems:

- CVE-2020-13845, boo#1174150 In Singularity 3.x versions below 3.6.0,

issues allow the ECL to be bypassed by a malicious user.

- CVE-2020-13846, boo#1174148 In Singularity 3.5 the --all / -a option

to singularity verify returns success even when some objects in a SIF

container are not signed,

or cannot be verified.

- CVE-2020-13847, boo#1174152 In Singularity 3.x versions below 3.6.0,

Singularity's sign and verify commands do not sign metadata found in

the global header or data object descriptors of a SIF file, allowing

an attacker to cause unexpected behavior. A signed container may

verify successfully, even when it has been modified in ways that could

be...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP2:

zypper in -t patch openSUSE-2020-1100=1

Package List

- openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64):

singularity-3.6.0-bp152.2.4.1

References

https://www.suse.com/security/cve/CVE-2020-13845.html

https://www.suse.com/security/cve/CVE-2020-13846.html

https://www.suse.com/security/cve/CVE-2020-13847.html

https://bugzilla.suse.com/1174148

https://bugzilla.suse.com/1174150

https://bugzilla.suse.com/1174152

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:1100-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here