CVE-2009-0876
Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink attack, which preserves setuid/setgid bits on Linux, related to DT_RPATH:$ORIGIN.
- Affected products
- Virtualbox
- Sun Xvm Virtualbox
- = 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, 2.1.4r42893
- CVSS 2.0
- 6.9 MEDIUM
- EPSS
- 0.8% (53th percentile)
- Weakness
- CWE-59
- NVD status
- Modified
- Published
- 2009-03-12
CVE-2009-0876 at NVD
1 known exploit for CVE-2009-0876
Proof-of-concept code and exploit modules indexed by Sploitus