CVE-2014-3641 PUBLISHED

The (1) GlusterFS and (2) Linux Smbfs drivers in OpenStack Cinder before 2014.1.3 allows remote authenticated users to obtain file data from the Cinder-volume host by cloning and attaching a volume with a crafted qcow2 header.

EPSS 0.33% · 55.8th percentile

Risk Scores

EPSS Score
0.33%
55.8th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTScinder0, 1:2013.2~rc3-0ubuntu1, 1:2013.2-0ubuntu1

Timeline

References

Open in Interactive Console →