Information disclosure in zfs - CVE-2015-3400

 

Information disclosure in zfs - CVE-2015-3400

Published: October 18, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38061
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2015-3400
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: openzfs
Affected software:
zfs

Detailed vulnerability description

The vulnerability allows a remote authenticated user to gain access to sensitive information.

sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to the shared zfs file system, which might allow remote authenticated users to obtain sensitive information by reading shared files.


How to mitigate CVE-2015-3400

Install update from vendor's website.

Sources