CVE-2015-3400

NameCVE-2015-3400
Descriptionsharenfs 0.6.4, when built with commits bcdd594 and 7d08880 from the zfs repository, provides world readable access to the shared zfs file system, which might allow remote authenticated users to obtain sensitive information by reading shared files.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
zfs-linux (PTS)buster/contrib0.7.12-2+deb10u2fixed
buster/contrib (security)0.7.12-2+deb10u3fixed
bullseye/contrib2.0.3-9+deb11u1fixed
bookworm/contrib2.1.11-1fixed
trixie/contrib2.2.3-1fixed
sid/contrib2.2.3-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
zfs-linuxsource(unstable)(not affected)

Notes

- zfs-linux <not-affected> (Specific to packages on archive.zfsonlinux.org repositories)
Issue with ZFS on Linux Debian packages specific as published in the archive.zfsonlinux.org repositories
https://github.com/zfsonlinux/zfs/issues/3319

Search for package or bug name: Reporting problems