SB2012061701 - Permissions, Privileges, and Access Controls in libvirt
Published: June 17, 2012 Updated: August 11, 2020
Security Bulletin ID
SB2012061701
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2012-2693)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.
Remediation
Install update from vendor's website.