• [gentoo-announce] [ GLSA 202210-19 ] Apptainer: Lack of Digital Signatu

    From glsamaker@gentoo.org@21:1/5 to All on Mon Oct 31 03:10:02 2022
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 202210-19
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    https://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Low
    Title: Apptainer: Lack of Digital Signature Hash Verification
    Date: October 31, 2022
    Bugs: #875869
    ID: 202210-19

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    A vulnerability has been found in Apptainer which could result in the
    usage of an unexpected of a container.

    Background
    ==========

    Apptainer is the container system for secure high-performance computing.

    Affected packages
    =================

    -------------------------------------------------------------------
    Package / Vulnerable / Unaffected
    -------------------------------------------------------------------
    1 app-containers/apptainer < 1.1.2 >= 1.1.2

    Description
    ===========

    The Go module "sif" version 2.8.0 and older, which is a statically
    linked dependency of Apptainer, does not verify that the hash
    algorithm(s) used are cryptographically secure when verifying digital signatures.

    Impact
    ======

    An image whose verification relies on a cryptographically insecure hash algorithm could be replaced, resulting in users using an image other
    than the one that was expected.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All Apptainer users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=app-containers/apptainer-1.1.2"

    References
    ==========

    [ 1 ] CVE-2022-39237
    https://nvd.nist.gov/vuln/detail/CVE-2022-39237

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

    https://security.gentoo.org/glsa/202210-19

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

    License
    =======

    Copyright 2022 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    https://creativecommons.org/licenses/by-sa/2.5
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmNfIUoACgkQFMQkOaVy +9m0RA/+IAeEon8f3p5BdYdLoDKkCZTC7YCOT7H/ncRxfmvAXRAFbTJKKjiPZvPc 657nN60v3qtOACZTDcycxAq65wtwWH08eqSLfxuI/o9TMAanA2vFDxxZB9MxGBSZ aZ6oW9hfPzHx5ttr+BKHb5ftoMp5fYpTiiYZ3OHHWIwwaiwMys7BHEh07wwEbFcg kO8D7WrNvAZFjlfcmlV0FRKsLODTDeYg/otjOUHz6za6/9jGn+04+/K3OrGxpAls uyUOkQgPdoz/v+u/DAtf5kS5HMwMWbIN2t5FN3E+VFFOkoJSzlEgcenrA+VktwMk cHE960EbTMakjQlBwCZ6RudQ2QCHzAydxIhLayv/stUjwLOj8RwZEkz87rIvg3q2 IGSXexWQe19hfTPIlAYQNe/lUN6ogcDOGyLgmIIbrOLdeXuFmu5sS3ipQxAxbwft VeuSSjCAnHcisnpbKamyp+erFM7wY+NOYVmGao932HvoK84Ac1aA7cfn68qpXlie H6kLLWNI0fvT66stYRlWf9sILHYGYE1mLGRUtsLetonAFx6FrW+3HBgD5srOkSIX wkUMEvkSkNnFcXNcbNvlD0CqRGYzH3TFEJ2AYG60aGZFQl6eEJEvvqnVhvFE7qr3 stQLwWVP6ZOPrVl2Iftsh+7VHMsJeJjSFImPKCspVzt9O5zsazk=
    =QIVn
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)