CVE Vulnerabilities

CVE-2020-13847

Improper Validation of Integrity Check Value

Published: Jul 14, 2020 | Modified: Jan 20, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Sylabs Singularity 3.0 through 3.5 lacks support for an Integrity Check. Singularitys sign and verify commands do not sign metadata found in the global header or data object descriptors of a SIF file.

Weakness

The product does not validate or incorrectly validates the integrity check values or “checksums” of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Affected Software

Name Vendor Start Version End Version
Singularity Sylabs 3.0.0 (including) 3.5.0 (including)
Singularity-container Ubuntu bionic *
Singularity-container Ubuntu eoan *
Singularity-container Ubuntu trusty *

Potential Mitigations

References