CVE-2019-11328
Aliases:GHSA-557g-r22w-9wvx
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 14 May 2019, 20:24
Last modified:04 Aug 2024, 22:48
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
9 HIGH
v2.0 (nvd)
EPSS Score
0.61% LOW
1% probability -0.24%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected
Timeline
14 May 2019, 20:24
Published
Vulnerability first disclosed
04 Aug 2024, 22:48
Last Modified
Vulnerability information updated
Description
An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious user with local/network access to the host system (e.g. ssh) could exploit this vulnerability due to insecure permissions allowing a user to edit files within `/run/singularity/instances/sing/<user>/<instance>`. The manipulation of those files can change the behavior of the starter-suid program when instances are joined resulting in potential privilege escalation on the host.
CVSS Metrics
- v3.1•HIGH•Score: 8.8CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v3.0•HIGH•Score: 8.8CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- v2.0•HIGH•Score: 9AV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS Trends
Current EPSS score: 0.61%• Percentile: 70%
Techniques & Countermeasures
- CWE-732•Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Affected Systems
- fedoraproject•fedora
28 | 29 | 30
- github.com/sylabs•singularity
≥ 3.1.0, < 3.2.0
- opensuse•backports
sle-15 | sle-15:sp1
- opensuse•leap
15.1
- sylabs•singularity
≥ 3.1.0, < 3.2.0 | 3.2.0 | 3.2.0:rc1 | 3.2.0:rc2
References (13)
- https://github.com/sylabs/singularity/releases/tag/v3.2.0
- http://www.openwall.com/lists/oss-security/2019/05/16/1
- http://www.securityfocus.com/bid/108360
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNU5BUHFOTYUZVHFUSX2VG4S3RCPUEMA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5O3TPL5OOTIZEI4H6IQBCCISBARJ6WL3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LIHV7DSEVTB5SUPEZ2UXGS3Q6WMEQSO2/
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00028.html
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html
- https://nvd.nist.gov/vuln/detail/CVE-2019-11328
- https://github.com/sylabs/singularity/commit/618c9d56802399adb329c23ea2b70598eaff4a31
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5O3TPL5OOTIZEI4H6IQBCCISBARJ6WL3
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LIHV7DSEVTB5SUPEZ2UXGS3Q6WMEQSO2
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNU5BUHFOTYUZVHFUSX2VG4S3RCPUEMA