Rebuild 3.8.5 using golang-1.16.12. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-7333cffa91 2021-12-24 01:23:26.059842 --------------------------------------------------------------------------------Name : singularity Product : Fedora 35 Version : 3.8.5 Release : 2.fc35 URL : https://singularity.hpcng.org Summary : Application and environment virtualization Description : Singularity provides functionality to make portable containers that can be used across host environments. --------------------------------------------------------------------------------Update Information: Rebuild 3.8.5 using golang-1.16.12 --------------------------------------------------------------------------------ChangeLog: * Tue Dec 14 2021 Dave Dykstra - 3.8.5-2 - Rebuild using golang-1.16.12 --------------------------------------------------------------------------------References: [ 1 ] Bug #2032683 - singularity-3.8.5 needs to be rebuilt with golang-1.16.12 https://bugzilla.redhat.com/show_bug.cgi?id=2032683 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-7333cffa91' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Rebuild 3.8.5 using golang-1.16.12. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-f6e491390b 2021-12-24 01:07:14.840716 --------------------------------------------------------------------------------Name : singularity Product : Fedora 34 Version : 3.8.5 Release : 2.fc34 URL : https://singularity.hpcng.org Summary : Application and environment virtualization Description : Singularity provides functionality to make portable containers that can be used across host environments. --------------------------------------------------------------------------------Update Information: Rebuild 3.8.5 using golang-1.16.12 --------------------------------------------------------------------------------ChangeLog: * Tue Dec 14 2021 Dave Dykstra - 3.8.5-2 - Rebuild using golang-1.16.12 --------------------------------------------------------------------------------References: [ 1 ] Bug #2032683 - singularity-3.8.5 needs to be rebuilt with golang-1.16.12 https://bugzilla.redhat.com/show_bug.cgi?id=2032683 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-f6e491390b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Upgrade to upstream security release 3.7.4. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-ac3ef133e8 2021-06-04 01:02:33.600109 --------------------------------------------------------------------------------Name : singularity Product : Fedora 33 Version : 3.7.4 Release : 1.fc33 URL : / Summary : Application and environment virtualization Description : Singularity provides functionality to make portable containers that can be used across host environments. --------------------------------------------------------------------------------Update Information: Upgrade to upstream security release 3.7.4 --------------------------------------------------------------------------------ChangeLog: * Wed May 26 2021 Dave Dykstra - 3.7.4-1 - Upgrade to upstream security release 3.7.4 --------------------------------------------------------------------------------References: [ 1 ] Bug #1965066 - singularity-3.7.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1965066 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-ac3ef133e8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for singularity ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0810-1 Rating: moderate References: #1184147 Cross-References: CVE-2021-29136 CVSS scores: CVE-2021-29136 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVE-2021-29136 (SUSE): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for singularity fixes the following issues: singularity was updated to version 3.7.3: - Fix for CVE-2021-29136: A dependency used to extract docker/OCI image layers can be tricked into modifying host files by creating a malicious layer that has a symlink with the name "." (or "/"), when running as root. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-810=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 s390x x86_64): singularity-3.7.3-bp152.2.19.3 References: https://www.suse.com/security/cve/CVE-2021-29136.html https://bugzilla.suse.com/1184147 . Keep your platforms secure with the recent Fedora security patch addressing a significant vulnerability in Podman.. openSUSE, singularity, security update, threat management, software patch. . LinuxSecurity.com Team
Upgrade to upstream security release 3.7.3. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-e49f5e66f8 2021-04-24 20:00:51.078312 --------------------------------------------------------------------------------Name : singularity Product : Fedora 34 Version : 3.7.3 Release : 1.fc34 URL : / Summary : Application and environment virtualization Description : Singularity provides functionality to make portable containers that can be used across host environments. --------------------------------------------------------------------------------Update Information: Upgrade to upstream security release 3.7.3 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 7 2021 Dave Dykstra - 3.7.3-1 - Upgrade to upstream security release 3.7.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1946970 - singularity-3.7.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1946970 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-e49f5e66f8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Upgrade to upstream security release 3.7.3. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-2e174e8a96 2021-04-16 14:42:40.037514 --------------------------------------------------------------------------------Name : singularity Product : Fedora 32 Version : 3.7.3 Release : 1.fc32 URL : / Summary : Application and environment virtualization Description : Singularity provides functionality to make portable containers that can be used across host environments. --------------------------------------------------------------------------------Update Information: Upgrade to upstream security release 3.7.3 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 7 2021 Dave Dykstra - 3.7.3-1 - Upgrade to upstream security release 3.7.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1946970 - singularity-3.7.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1946970 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-2e174e8a96' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Upgrade to upstream security release 3.7.3. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-601ee898f7 2021-04-16 14:33:16.807391 --------------------------------------------------------------------------------Name : singularity Product : Fedora 33 Version : 3.7.3 Release : 1.fc33 URL : Summary : Application and environment virtualization Description : Singularity provides functionality to make portable containers that can be used across host environments. --------------------------------------------------------------------------------Update Information: Upgrade to upstream security release 3.7.3 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 7 2021 Dave Dykstra - 3.7.3-1 - Upgrade to upstream security release 3.7.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1946970 - singularity-3.7.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=1946970 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-601ee898f7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for singularity ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1814-1 Rating: important References: #1177901 Cross-References: CVE-2020-15229 Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for singularity fixes the following issues: Update to new version 3.6.4: - CVE-2020-15229: Due to insecure handling of path traversal and the lack of path sanitization within unsquashfs, it is possible to overwrite/create files on the host filesystem during the extraction of a crafted squashfs filesystem (boo#1177901). This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2020-1814=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): singularity-3.6.4-bp152.2.12.1 References: https://www.suse.com/security/cve/CVE-2020-15229.html https://bugzilla.suse.com/1177901 -- . A security patch for singularity addresses a path traversal vulnerability in openSUSE. For more information, refer to advisory ID: openSUSE-SU-2020:1814-2.. OpenSUSE, Security Update, Path Traversal, Important Fix, Singularity Update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.