CVE-2012-2693: Low severity redhat libvirt vulnerability
libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2693?
CVE-2012-2693 is classified as a medium severity vulnerability.
How do I fix CVE-2012-2693?
To fix CVE-2012-2693, update libvirt to version 0.9.12 or later.
Who is affected by CVE-2012-2693?
CVE-2012-2693 affects users of libvirt versions prior to 0.9.12, particularly those using USB devices with the same vendor and product ID.
What vulnerabilities does CVE-2012-2693 exploit?
CVE-2012-2693 exploits a flaw in the device assignment logic of libvirt, leading to incorrect USB device association.
Is CVE-2012-2693 a remote or local vulnerability?
CVE-2012-2693 is a local vulnerability, allowing local users to access unintended USB devices.