Information disclosure in zfs - CVE-2015-3400

 

Information disclosure in zfs - CVE-2015-3400

Published: October 18, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38061
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-3400
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

sharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to the shared zfs file system, which might allow remote authenticated users to obtain sensitive information by reading shared files.


Affected software

zfs

How to mitigate CVE-2015-3400

Install update from vendor's website.


External References

Related Security Bulletins