Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-29499

Опубликовано: 07 мая 2021
Источник: debian
EPSS Низкий

Описание

SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the version of the `github.com/satori/go.uuid` module used as a dependency. A patch is available in version >= v1.2.3 of the module. Users are encouraged to upgrade. As a workaround, users passing CreateInfo struct should ensure the `ID` field is generated using a version of `github.com/satori/go.uuid` that is not vulnerable to this issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-sylabs-siffixed2.3.1-1experimentalpackage
golang-github-sylabs-siffixed2.3.1-2package
golang-github-sylabs-sifno-dsabullseyepackage

Примечания

  • https://github.com/sylabs/sif/security/advisories/GHSA-4gh8-x3vv-phhg

EPSS

Процентиль: 54%
0.00317
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the version of the `github.com/satori/go.uuid` module used as a dependency. A patch is available in version >= v1.2.3 of the module. Users are encouraged to upgrade. As a workaround, users passing CreateInfo struct should ensure the `ID` field is generated using a version of `github.com/satori/go.uuid` that is not vulnerable to this issue.

CVSS3: 7.5
nvd
больше 4 лет назад

SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the version of the `github.com/satori/go.uuid` module used as a dependency. A patch is available in version >= v1.2.3 of the module. Users are encouraged to upgrade. As a workaround, users passing CreateInfo struct should ensure the `ID` field is generated using a version of `github.com/satori/go.uuid` that is not vulnerable to this issue.

CVSS3: 7.5
github
больше 4 лет назад

Predictable SIF UUID Identifiers in github.com/sylabs/sif

CVSS3: 7.5
fstec
почти 8 лет назад

Уязвимость модуля github.com/satori/go.uuid реализации Singularity Image Format SIF, связанная с использованием недостаточно случайных значений, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 54%
0.00317
Низкий