6.9

CVE-2009-0876

Exploit

Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink attack, which preserves setuid/setgid bits on Linux, related to DT_RPATH:$ORIGIN.

Data is provided by the National Vulnerability Database (NVD)
SunXvm Virtualbox Version2.0.0
   LinuxLinux Kernel
SunXvm Virtualbox Version2.0.2
   LinuxLinux Kernel
SunXvm Virtualbox Version2.0.4
   LinuxLinux Kernel
SunXvm Virtualbox Version2.0.6r39760
   LinuxLinux Kernel
SunXvm Virtualbox Version2.1.0
   LinuxLinux Kernel
SunXvm Virtualbox Version2.1.2
   LinuxLinux Kernel
SunXvm Virtualbox Version2.1.4r42893
   LinuxLinux Kernel
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.3% 0.501
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.