Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2014-3519 Details

Description

The open_by_handle_at function in vzkernel before 042stab090.5 in the OpenVZ modification for the Linux kernel 2.6.32, when using simfs, might allow local container users with CAP_DAC_READ_SEARCH capability to bypass an intended container protection mechanism and access arbitrary files on a filesystem via vectors related to use of the file_handle structure.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://help.virtuozzo.com/customer/en/portal/articles/2522783-parallels-cloud-server-6-0-update-6-hotfix-8-6-0-6-2004- CVERelease NotesVendor Advisory
https://help.virtuozzo.com/customer/en/portal/articles/2563842-cu-2-6-32-042stab090-5-parallels-virtuozzo-containers-4-7-core-update CVERelease NotesVendor Advisory
https://help.virtuozzo.com/customer/en/portal/articles/2563843-cu-2-6-32-042stab090-5-parallels-server-bare-metal-5-0-core-update CVERelease NotesVendor Advisory
https://openvz.org/Download/kernel/rhel6/042stab090.5 CVEPatchRelease NotesVendor Advisory
http://www.openwall.com/lists/oss-security/2014/06/24/16 CVEMailing ListMitigationThird Party Advisory

see all 12 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-284Improper Access Control[email protected]

Affected Products

ProductVersions
openvz vzkernel
2.6.32

CPE

  • cpe:2.3:o:openvz:vzkernel:2.6.32:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2014-3519
NVD Published Date:
Feb 1, 2018
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2014-3519 Details - Not Deferred