Improper validation of integrity check value in Singularity - CVE-2020-13847

 

Improper validation of integrity check value in Singularity - CVE-2020-13847

Published: July 21, 2020


Vulnerability identifier: #VU31718
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13847
CWE-ID: CWE-354
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to Singularity's sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file. A remote attacker can cause unexpected behavior.


Affected software

Singularity
singularity (Alpine package)
SUSE Linux
Opensuse

How to mitigate CVE-2020-13847

Install updates from vendor's website.

Singularity - update to 3.6.0
singularity (Alpine package) - update to 3.6.2-r0

External References

Related Security Bulletins