CVE-2014-3641: Infoleak
Published Oct 8, 2014
·Updated
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
Affected Software
2 affected components
Openstack Cinder<=2014.1.2
Openstack Cinder=2014.1.1
Event History
Oct 8, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-3641?
CVE-2014-3641 has a medium severity level due to the ability of remote authenticated users to access sensitive file data.
2
How do I fix CVE-2014-3641?
To fix CVE-2014-3641, upgrade OpenStack Cinder to version 2014.1.3 or later.
3
Who is affected by CVE-2014-3641?
Users running OpenStack Cinder versions prior to 2014.1.3 are affected by CVE-2014-3641.
4
What is the impact of CVE-2014-3641?
The impact of CVE-2014-3641 allows unauthorized file data access when a volume with a crafted qcow2 header is used.
5
Can CVE-2014-3641 be exploited remotely?
Yes, CVE-2014-3641 can be exploited by remote authenticated users with malicious intent.