Sylabs Singularity 3.0 through 3.5 has Improper Validation of an Integrity Check Value. Image integrity is not validated when an ECL policy is enforced. The fingerprint required by the ECL is compared against the signature object descriptor(s) in the SIF file, rather than to a cryptographically validated signature.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-07-14T17:23:08

Updated: 2020-09-18T18:06:11

Reserved: 2020-06-04T00:00:00


Link: CVE-2020-13845

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-07-14T18:15:14.383

Modified: 2023-01-20T20:09:21.213


Link: CVE-2020-13845

JSON object: View

cve-icon Redhat Information

No data.