First published: Wed Oct 08 2014(Updated: )
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenStack Cinder | <=2014.1.2 | |
Red Hat OpenStack Cinder | =2014.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3641 has a medium severity level due to the ability of remote authenticated users to access sensitive file data.
To fix CVE-2014-3641, upgrade OpenStack Cinder to version 2014.1.3 or later.
Users running OpenStack Cinder versions prior to 2014.1.3 are affected by CVE-2014-3641.
The impact of CVE-2014-3641 allows unauthorized file data access when a volume with a crafted qcow2 header is used.
Yes, CVE-2014-3641 can be exploited by remote authenticated users with malicious intent.