![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.852060 |
Category: | SuSE Local Security Checks |
Title: | openSUSE: Security Advisory for singularity (openSUSE-SU-2018:3316-1) |
Summary: | The remote host is missing an update for the 'singularity'; package(s) announced via the openSUSE-SU-2018:3316-1 advisory. |
Description: | Summary: The remote host is missing an update for the 'singularity' package(s) announced via the openSUSE-SU-2018:3316-1 advisory. Vulnerability Insight: Singularity was updated to version 2.6.0, bringing features, bugfixes and security fixes. Security issues fixed: - CVE-2018-12021: Fixed access control on systems supporting overlay file system (boo#1100333). Highlights of 2.6.0: - Allow admin to specify a non-standard location for mksquashfs binary at build time with '--with-mksquashfs' option. - '--nv' can be made default with all action commands in singularity.conf - '--nv' can be controlled by env vars '$SINGULARITY_NV' and '$SINGULARITY_NV_OFF' - Restore shim init process for proper signal handling and child reaping when container is initiated in its own PID namespace - Add '-i' option to image.create to specify the inode ratio. - Bind '/dev/nvidia*' into the container when the '--nv' flag is used in conjunction with the '--contain' flag - Add '--no-home' option to not mount user $HOME if it is not the $CWD and 'mount home = yes' is set. - Added support for OAUTH2 Docker registries like Azure Container Registry Highlights of 2.5.2: - a new `build` command was added to replace `create` + `bootstrap` - default image format is squashfs, eliminating the need to specify a size - a `localimage` can be used as a build base, including ext3, sandbox, and other squashfs images - singularity hub can now be used as a base with the uri - Restore docker-extract aufs whiteout handling that implements correct extraction of docker container layers. Bug fixes: - Fix 404 when using Arch Linux bootstrap - Fix environment variables clearing while starting instances - several more bug fixes, see CHANGELOG.md for details Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or 'zypper patch'. Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1223=1 - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2018-1223=1 Affected Software/OS: singularity on openSUSE Leap 15.0. Solution: Please install the updated package(s). CVSS Score: 6.8 CVSS Vector: AV:N/AC:L/Au:S/C:C/I:N/A:N |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2018-12021 http://www.openwall.com/lists/oss-security/2019/05/16/1 |
Copyright | Copyright (C) 2018 Greenbone Networks GmbH |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |