UBUNTU-CVE-2021-29499
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-29499
Summary:
Details: SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the version of the `github.com/satori/go.uuid` module used as a dependency. A patch is available in version >= v1.2.3 of the module. Users are encouraged to upgrade. As a workaround, users passing CreateInfo struct should ensure the `ID` field is generated using a version of `github.com/satori/go.uuid` that is not vulnerable to this issue.
References: https://ubuntu.com/security/CVE-2021-29499, https://github.com/sylabs/sif/security/advisories/GHSA-4gh8-x3vv-phhg, https://www.cve.org/CVERecord?id=CVE-2021-29499, https://github.com/sylabs/sif/commit/193962882122abf85ff5f5bcc86404933e71c07d
Affected packages
Package
Name: singularity-container
Purl: pkg:deb/ubuntu/singularity-container?arch=source&distro=esm-apps%2Fbionic
Affected ranges
Type: ECOSYSTEM
Events:
