CVE-2014-3641

The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:cinder:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:cinder:2014.1.1:*:*:*:*:*:*:*

History

13 Feb 2023, 00:41

Type Values Removed Values Added
Summary CVE-2014-3641 openstack-cinder: Cinder-volume host data leak to virtual machine instance The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
References
  • {'url': 'https://bugzilla.redhat.com/show_bug.cgi?id=1141996', 'name': 'https://bugzilla.redhat.com/show_bug.cgi?id=1141996', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2014:1788', 'name': 'https://access.redhat.com/errata/RHSA-2014:1788', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2014:1787', 'name': 'https://access.redhat.com/errata/RHSA-2014:1787', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/security/cve/CVE-2014-3641', 'name': 'https://access.redhat.com/security/cve/CVE-2014-3641', 'tags': [], 'refsource': 'MISC'}

02 Feb 2023, 20:18

Type Values Removed Values Added
Summary The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header. CVE-2014-3641 openstack-cinder: Cinder-volume host data leak to virtual machine instance
References
  • (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=1141996 -
  • (MISC) https://access.redhat.com/errata/RHSA-2014:1788 -
  • (MISC) https://access.redhat.com/errata/RHSA-2014:1787 -
  • (MISC) https://access.redhat.com/security/cve/CVE-2014-3641 -

Information

Published : 2014-10-08 19:55

Updated : 2023-12-10 11:31


NVD link : CVE-2014-3641

Mitre link : CVE-2014-3641

CVE.ORG link : CVE-2014-3641


JSON object : View

Products Affected

openstack

  • cinder
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor