Safety vulnerability ID: 35566
The information on this page was manually curated by our Cybersecurity Intelligence Team.
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
Latest version: 25.0.0
OpenStack Block Storage
The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.
MLIST:[oss-security] 20141002 [OSSA 2014-033] Cinder-volume host data leak to vm instance (CVE-2014-3641): http://seclists.org/oss-sec/2014/q4/78
CONFIRM:https://bugs.launchpad.net/cinder/+bug/1350504: https://bugs.launchpad.net/cinder/+bug/1350504
REDHAT:RHSA-2014:1787: http://rhn.redhat.com/errata/RHSA-2014-1787.html
REDHAT:RHSA-2014:1788: http://rhn.redhat.com/errata/RHSA-2014-1788.html
UBUNTU:USN-2405-1: http://www.ubuntu.com/usn/USN-2405-1
BID:70221: http://www.securityfocus.com/bid/70221
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application