CVE-2014-3632: High severity neutron vulnerability
The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stack Platform 5.0 for Red Hat Enterprise Linux 6, allows remote attackers to gain privileges via a crafted configuration file. NOTE: this vulnerability exists because of a CVE-2013-6433 regression.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3632?
CVE-2014-3632 is considered a critical vulnerability that can allow remote attackers to gain elevated privileges.
How do I fix CVE-2014-3632?
To fix CVE-2014-3632, ensure that the OpenStack Neutron package is updated to version 2014.1.2-4 or later.
What systems are affected by CVE-2014-3632?
CVE-2014-3632 affects the OpenStack Neutron package in Red Hat Enterprise Linux OpenStack Platform 5.0 and earlier versions.
Can CVE-2014-3632 be exploited remotely?
Yes, CVE-2014-3632 can be exploited remotely due to vulnerabilities in the default sudoers configuration.
Is there a workaround for CVE-2014-3632?
A workaround for CVE-2014-3632 involves manually configuring the sudoers file to restrict privilege escalation until the software is updated.