CVE-2012-2693

critical

Description

libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.

References

https://www.redhat.com/archives/libvir-list/2012-April/msg01494.html

http://www.openwall.com/lists/oss-security/2012/06/11/3

http://www.openwall.com/lists/oss-security/2012/06/11/2

http://rhn.redhat.com/errata/RHSA-2013-0127.html

http://rhn.redhat.com/errata/RHSA-2012-0748.html

Details

Source: Mitre, NVD

Published: 2012-06-17

Updated: 2013-01-15

Risk Information

CVSS v2

Base Score: 3.7

Vector: CVSS2#AV:L/AC:H/Au:N/C:P/I:P/A:P

Severity: Low

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical