Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-2693
Description:libvirt, possibly before 0.9.12, does not properly assign USB devices to virtual machines when multiple devices have the same vendor and product ID, which might cause the wrong device to be associated with a guest and might allow local users to access unintended USB devices.
Test IDs: 1.3.6.1.4.1.25623.1.0.881576   1.3.6.1.4.1.25623.1.0.72355   1.3.6.1.4.1.25623.1.0.71401   1.3.6.1.4.1.25623.1.0.870772   1.3.6.1.4.1.25623.1.0.881097   1.3.6.1.4.1.25623.1.0.123749   1.3.6.1.4.1.25623.1.0.123885  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-2693
RHSA-2012:0748
http://rhn.redhat.com/errata/RHSA-2012-0748.html
RHSA-2013:0127
http://rhn.redhat.com/errata/RHSA-2013-0127.html
[libvirt] 20120428 [PATCH 0/3] usb devices with same vendor, productID hotplug support
https://www.redhat.com/archives/libvir-list/2012-April/msg01494.html
[oss-security] 20120611 CVE request -- libvirt: address bus= device= when identicle vendor ID/product IDs usb devices attached are ignored
http://www.openwall.com/lists/oss-security/2012/06/11/2
[oss-security] 20120611 Re: CVE request -- libvirt: address bus= device= when identicle vendor ID/product IDs usb devices attached are ignored
http://www.openwall.com/lists/oss-security/2012/06/11/3




© 1998-2025 E-Soft Inc. All rights reserved.