SB2012061701 - Permissions, Privileges, and Access Controls in libvirt 



SB2012061701 - Permissions, Privileges, and Access Controls in libvirt

Published: June 17, 2012 Updated: August 11, 2020

Security Bulletin ID SB2012061701
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2012-2693)

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.


Remediation

Install update from vendor's website.