Bug#929042: singularity-container: CVE-2019-11328)

2019-05-16 Thread Salvatore Bonaccorso
Hi Afif, On Thu, May 16, 2019 at 12:59:55PM -0400, Afif Elghraoui wrote: > > > On May 15, 2019 5:13:24 PM EDT, Salvatore Bonaccorso > wrote: > >Hi Afif, > > > >On Wed, May 15, 2019 at 10:57:49PM +0200, Salvatore Bonaccorso wrote: > >> Then there is nothing further to be done. > > > >Oh,

Bug#929042: singularity-container: CVE-2019-11328)

2019-05-16 Thread Afif Elghraoui
On May 15, 2019 5:13:24 PM EDT, Salvatore Bonaccorso wrote: >Hi Afif, > >On Wed, May 15, 2019 at 10:57:49PM +0200, Salvatore Bonaccorso wrote: >> Then there is nothing further to be done. > >Oh, actually there is an open point: Is it confirmed that 3.0.3 is not >affected by the CVE? Did you

Bug#929042: closed by Afif Elghraoui (Re: Bug#929042: singularity-container: CVE-2019-11328)

2019-05-15 Thread Afif Elghraoui
على ١٠‏/٩‏/١٤٤٠ هـ ‫٥:١٣ م، كتب Salvatore Bonaccorso: > Hi Afif, > > On Wed, May 15, 2019 at 10:57:49PM +0200, Salvatore Bonaccorso wrote: >> Then there is nothing further to be done. > > Oh, actually there is an open point: Is it confirmed that 3.0.3 is not > affected by the CVE? Did you got

Bug#929042: closed by Afif Elghraoui (Re: Bug#929042: singularity-container: CVE-2019-11328)

2019-05-15 Thread Afif Elghraoui
على ١٠‏/٩‏/١٤٤٠ هـ ‫٤:٥٧ م، كتب Salvatore Bonaccorso: >>> Could you furthermore check, is this only introduced in the 3.1.0 >>> series really or just are those the versions checked for the issue, >>> but earlier versions might be affected as well? >>> >> I filed an unblock request to hopefully

Bug#929042: closed by Afif Elghraoui (Re: Bug#929042: singularity-container: CVE-2019-11328)

2019-05-15 Thread Salvatore Bonaccorso
Hi Afif, On Wed, May 15, 2019 at 10:57:49PM +0200, Salvatore Bonaccorso wrote: > Then there is nothing further to be done. Oh, actually there is an open point: Is it confirmed that 3.0.3 is not affected by the CVE? Did you got any information why this is only introduced in 3.1.0? Regards,

Bug#929042: closed by Afif Elghraoui (Re: Bug#929042: singularity-container: CVE-2019-11328)

2019-05-15 Thread Salvatore Bonaccorso
s email. > > > -- > 929042: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=929042 > Debian Bug Tracking System > Contact ow...@bugs.debian.org with problems > Date: Wed, 15 May 2019 16:51:24 -0400 > From: Afif Elghraoui > To: 929042-d...@bugs.debian.org > Subject: Re: Bug#92

Bug#929042: singularity-container: CVE-2019-11328

2019-05-15 Thread Salvatore Bonaccorso
Source: singularity-container Version: 3.1.1+ds-1 Severity: grave Tags: security upstream Hi, The following vulnerability was published for singularity-container. CVE-2019-11328[0]: | An issue was discovered in Singularity 3.1.0 to 3.2.0-rc2, a malicious | user with local/network access to the