Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-39237

Опубликовано: 06 окт. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.3

Описание

syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the github.com/sylabs/sif/v2/pkg/integrity package did not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures. A patch is available in version >= v2.8.1 of the module. Users are encouraged to upgrade. Users unable to upgrade may independently validate that the hash algorithm(s) used for metadata digest(s) and signature hash are cryptographically secure.

РелизСтатусПримечание
bionic

DNE

devel

not-affected

code not present
esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

not-affected

code not present
focal

ignored

end of standard support, was needed
jammy

needed

kinetic

ignored

end of life, was needs-triage
lunar

ignored

end of life, was needs-triage
mantic

ignored

end of life, was needs-triage

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

needs-triage

esm-apps/bionic

needs-triage

esm-apps/noble

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

needs-triage

oracular

ignored

end of life, was needs-triage
plucky

ignored

end of life, was needs-triage

Показывать по

EPSS

Процентиль: 47%
0.00239
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
nvd
больше 3 лет назад

syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures. A patch is available in version >= v2.8.1 of the module. Users are encouraged to upgrade. Users unable to upgrade may independently validate that the hash algorithm(s) used for metadata digest(s) and signature hash are cryptographically secure.

CVSS3: 6.3
debian
больше 3 лет назад

syslabs/sif is the Singularity Image Format (SIF) reference implementa ...

CVSS3: 6.3
github
больше 3 лет назад

SIF's Digital Signature Hash Algorithms Not Validated

suse-cvrf
около 3 лет назад

Security update for apptainer

EPSS

Процентиль: 47%
0.00239
Низкий

6.3 Medium

CVSS3