This update for singularity fixes the following issues:
New version 3.6.3, addresses the following security issues:
- CVE-2020-25039, boo#1176705
When a Singularity action command (run, shell, exec) is run with the
fakeroot or user namespace option, Singularity will extract a container
image to a temporary sandbox directory. Due to insecure permissions on the
temporary directory it is possible for any user with access to the system
to read the contents of the image. Additionally, if the image contains a
world-writable file or directory, it is possible for a user to inject
arbitrary content into the running container.
- CVE-2020-25040, boo#1176707
When a Singularity command that results in a container build operation
is executed, it is possible for a user with access to the system to read
the contents of the image during the build. Additionally, if the image
contains a world-writable file or directory, it is possible for a user to
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2020-1497=1
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-1497=1
- openSUSE Leap 15.2 (x86_64):
singularity-3.6.3-lp152.2.6.1
singularity-debuginfo-3.6.3-lp152.2.6.1
- openSUSE Leap 15.1 (x86_64):
singularity-3.6.3-lp151.2.9.1
singularity-debuginfo-3.6.3-lp151.2.9.1
https://www.suse.com/security/cve/CVE-2020-25039.html
https://www.suse.com/security/cve/CVE-2020-25040.html
https://bugzilla.suse.com/1176705
https://bugzilla.suse.com/1176707
--
Get the latest Linux and open source security news straight to your inbox.