SIF's Digital Signature Hash Algorithms Not Validated
Description
Published by the National Vulnerability Database
Oct 6, 2022
Published to the GitHub Advisory Database
Oct 6, 2022
Reviewed
Oct 6, 2022
Last updated
Feb 17, 2023
Impact
The
github.com/sylabs/sif/v2/pkg/integrity
package does not verify that the hash algorithm(s) used are cryptographically secure when verifying digital signatures.Patches
A patch is available in version >= v2.8.1 of the module. Users are encouraged to upgrade.
The patch is commit sylabs/sif@07fb860
Workarounds
Users may independently validate that the hash algorithm(s) used for metadata digest(s) and signature hash are cryptographically secure.
References
For more information
If you have any questions or comments about this advisory:
References