This update for singularity fixes the following issues:
New version 3.6.3, addresses the following security issues:
- CVE-2020-25039, boo#1176705
When a Singularity action command (run, shell, exec) is run with the
fakeroot or user namespace option, Singularity will extract a container
image to a temporary sandbox directory. Due to insecure permissions on the
temporary directory it is possible for any user with access to the system
to read the contents of the image. Additionally, if the image contains a
world-writable file or directory, it is possible for a user to inject
arbitrary content into the running container.
- CVE-2020-25040, boo#1176707
When a Singularity command that results in a container build operation
is executed, it is possible for a user with access to the system to read
the contents of the image during the build. Additionally, if the image
contains a world-writable file or directory, it is possible for a user to
...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP2:
zypper in -t patch openSUSE-2020-1529=1
- openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64):
singularity-3.6.3-bp152.2.8.1
https://www.suse.com/security/cve/CVE-2020-25039.html
https://www.suse.com/security/cve/CVE-2020-25040.html
https://bugzilla.suse.com/1176705
https://bugzilla.suse.com/1176707
--
Get the latest Linux and open source security news straight to your inbox.