libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:39
Type | Values Removed | Values Added |
---|---|---|
References | () http://rhn.redhat.com/errata/RHSA-2012-0748.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2013-0127.html - | |
References | () http://www.openwall.com/lists/oss-security/2012/06/11/2 - | |
References | () http://www.openwall.com/lists/oss-security/2012/06/11/3 - | |
References | () https://www.redhat.com/archives/libvir-list/2012-April/msg01494.html - Patch |
Information
Published : 2012-06-17 03:41
Updated : 2024-11-21 01:39
NVD link : CVE-2012-2693
Mitre link : CVE-2012-2693
CVE.ORG link : CVE-2012-2693
JSON object : View
Products Affected
redhat
- libvirt
CWE
CWE-264
Permissions, Privileges, and Access Controls