Debian Golang-Github-Sylabs-Sif vulnerabilities
2 known vulnerabilities affecting debian/golang-github-sylabs-sif.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-39237MEDIUMCVSS 6.3fixed in golang-github-sylabs-sif 2.8.3-1 (bookworm)2022
CVE-2022-39237 [MEDIUM] CVE-2022-39237: golang-github-sylabs-sif - syslabs/sif is the Singularity Image Format (SIF) reference implementation. In v...
syslabs/sif is the Singularity Image Format (SIF) reference implementation. In versions prior to 2.8.1the `github.com/sylabs/sif/v2/pkg/integrity` package did not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures. A patch is available in version >= v2.8.1 of the module. Users are encouraged to up
debian
CVE-2021-29499HIGHCVSS 7.5fixed in golang-github-sylabs-sif 2.3.1-2 (bookworm)2021
CVE-2021-29499 [HIGH] CVE-2021-29499: golang-github-sylabs-sif - SIF is an open source implementation of the Singularity Container Image Format. ...
SIF is an open source implementation of the Singularity Container Image Format. The `siftool new` command and func siftool.New() produce predictable UUID identifiers due to insecure randomness in the version of the `github.com/satori/go.uuid` module used as a dependency. A patch is available in version >= v1.2.3 of the module. Users are encouraged t
debian