Vulnerability Name:

CVE-2020-25039 (CCN-188350)

Assigned:2020-09-15
Published:2020-09-15
Updated:2021-07-21
Summary:Sylabs Singularity 3.2.0 through 3.6.2 has Insecure Permissions on temporary directories used in fakeroot or user namespace container execution.
CVSS v3 Severity:8.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
7.1 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): None
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:C/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): None
Vulnerability Type:CWE-732
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2020-25039

Source: SUSE
Type: Third Party Advisory
openSUSE-SU-2020:1497

Source: SUSE
Type: Third Party Advisory
openSUSE-SU-2020:1529

Source: XF
Type: UNKNOWN
sylabs-cve202025039-sec-bypass(188350)

Source: CCN
Type: Singularity GIT Repository
Execution Control List (ECL) Is Insecure

Source: CCN
Type: Singularity GIT Repository
Insecure permissions on user namespace / fakeroot temporary rootfs

Source: MISC
Type: Mitigation, Third Party Advisory
https://github.com/hpcng/singularity/security/advisories/GHSA-w6v2-qchm-grj7

Source: MISC
Type: Product
https://medium.com/sylabs

Oval Definitions
Definition IDClassTitleLast Modified
oval:org.opensuse.security:def:202025039
V
CVE-2020-25039
2022-06-30
oval:org.opensuse.security:def:113439
P
singularity-3.8.3-1.2 on GA media (Moderate)
2022-01-17
oval:org.opensuse.security:def:64832
P
Security update for the Linux Kernel (Important) (in QA)
2022-01-07
oval:org.opensuse.security:def:64622
P
Security update for python-Pygments (Important)
2021-12-01
oval:org.opensuse.security:def:64623
P
Security update for speex (Moderate)
2021-12-01
oval:org.opensuse.security:def:106840
P
singularity-3.8.3-1.2 on GA media (Moderate)
2021-10-01
oval:org.opensuse.security:def:63478
P
java-11-openjdk-javadoc-11.0.10.0-3.53.1 on GA media (Moderate)
2021-08-10
oval:org.opensuse.security:def:63340
P
libfreebl3-hmac-3.53.1-3.51.1 on GA media (Moderate)
2021-08-10
oval:org.opensuse.security:def:64730
P
Security update for sqlite3 (Important)
2021-07-14
oval:org.opensuse.security:def:64890
P
Security update for containerd, docker, runc (Important)
2021-06-11
oval:org.opensuse.security:def:62859
P
libpcp-devel-3.11.9-3.116 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:64486
P
Security update for permissions (Important)
2021-05-04
oval:org.opensuse.security:def:63075
P
ntp-4.2.8p13-4.6.1 on GA media (Moderate)
2021-04-29
oval:org.opensuse.security:def:64527
P
Security update for permissions (Moderate)
2021-01-22
oval:org.opensuse.security:def:63107
P
apache2-mod_wsgi-4.5.18-2.27 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:63578
P
gnome-shell-calendar-3.26.2+20180130.0d9c74212-4.16.1 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:62659
P
libXvnc-devel-1.9.0-19.6.1 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:62658
P
libXt6-32bit-1.1.5-2.24 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:63082
P
libcgroup-devel-0.41.rc1-1.10.1 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:64271
P
Security update for xen (Important)
2020-12-03
oval:org.opensuse.security:def:63285
P
libwsman-devel-2.6.7-3.6.1 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:62682
P
libmms-devel-0.6.4-1.24 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:63138
P
389-ds-1.4.0.3-2.39 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:63079
P
gv-3.7.4-1.41 on GA media (Moderate)
2020-12-03
oval:org.opensuse.security:def:74944
P
Security update for python3 (Important)
2020-12-01
oval:org.opensuse.security:def:64373
P
libproxy-devel on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:64031
P
Security update for MozillaFirefox (Important)
2020-12-01
oval:org.opensuse.security:def:63928
P
Security update for libvirt (Important)
2020-12-01
oval:org.opensuse.security:def:74593
P
Security update for singularity (Moderate)
2020-12-01
oval:org.opensuse.security:def:65002
P
Security update for java-11-openjdk (Important)
2020-12-01
oval:org.opensuse.security:def:63704
P
Security update for ghostscript (Important)
2020-12-01
oval:org.opensuse.security:def:75077
P
Security update for singularity (Moderate)
2020-12-01
oval:org.opensuse.security:def:64415
P
logrotate on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:64165
P
Security update for spice-gtk (Moderate)
2020-12-01
oval:org.opensuse.security:def:63781
P
Security update for openldap2 (Moderate)
2020-12-01
oval:org.opensuse.security:def:74467
P
Security update for djvulibre (Moderate)
2020-12-01
oval:org.opensuse.security:def:64157
P
Security update for java-1_7_0-openjdk (Important)
2020-12-01
oval:org.opensuse.security:def:109715
P
Security update for singularity (Moderate)
2020-09-25
oval:org.opensuse.security:def:96368
P
Security update for singularity (Moderate)
2020-09-25
oval:org.opensuse.security:def:103058
P
Security update for singularity (Moderate)
2020-09-25
oval:org.opensuse.security:def:110217
P
Security update for singularity (Moderate)
2020-09-21
oval:org.opensuse.security:def:110772
P
Security update for singularity (Moderate)
2020-09-21
BACK