Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-19724

Опубликовано: 18 дек. 2019
Источник: debian
EPSS Низкий

Описание

Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
singularity-containerfixed3.5.2+ds1-1package

Примечания

  • https://github.com/sylabs/singularity/commit/2cda4981812c29f0fb11d3ea6aaf6139f665a631

EPSS

Процентиль: 54%
0.00313
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.

CVSS3: 7.5
nvd
около 6 лет назад

Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.

suse-cvrf
около 6 лет назад

Security update for singularity

CVSS3: 7.5
github
больше 3 лет назад

Singularity insecure permissions

suse-cvrf
больше 5 лет назад

Security update for singularity

EPSS

Процентиль: 54%
0.00313
Низкий