Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://github.com/sylabs/singularity/releases/tag/v3.5.2 | third party advisory release notes |
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00025.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00059.html | vendor advisory |