Vulnerability Name:

CVE-2009-0876 (CCN-49193)

Assigned:2009-02-26
Published:2009-02-26
Updated:2017-08-17
Summary:Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink attack, which preserves setuid/setgid bits on Linux, related to DT_RPATH:$ORIGIN.
Per: http://sunsolve.sun.com/search/document.do?assetkey=1-66-254568-1

"5. Resolution

This issue is addressed in the following releases:

Linux

* Sun xVM VirtualBox 2.0.6r43001
* Sun xVM VirtualBox 2.1.4r43001"
CVSS v3 Severity:8.2 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.9 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C)
5.1 Medium (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-59
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2009-0876

Source: OSVDB
Type: UNKNOWN
52580

Source: CCN
Type: SA34232
Sun xVM VirtualBox Privilege Escalation Vulnerability

Source: SECUNIA
Type: Vendor Advisory
34232

Source: CCN
Type: SECTRACK ID: 1021841
Sun xVM VirtualBox Lets Local Users Gain Root Privileges

Source: CCN
Type: Sun Alert ID: 254568
Security Vulnerability in Sun xVM VirtualBox for the Linux Platform may Lead to Escalation of Privileges

Source: SUNALERT
Type: Patch, Vendor Advisory
254568

Source: CCN
Type: ASA-2009-094
Security Vulnerability in Sun xVM VirtualBox for the Linux Platform may Lead to Escalation of Privileges (Sun 254568)

Source: MLIST
Type: UNKNOWN
[oss-security] 20090316 CVE-2009-0876 (VirtualBox) references

Source: MLIST
Type: UNKNOWN
[oss-security] 20090317 Re: CVE-2009-0876 (VirtualBox) references

Source: CCN
Type: OSVDB ID: 52580
Sun xVM VirtualBox for Linux Unspecified Local Privilege Escalation

Source: BID
Type: Exploit
34080

Source: CCN
Type: BID-34080
Sun xVM VirtualBox Local Privilege Escalation Vulnerability

Source: SECTRACK
Type: UNKNOWN
1021841

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.virtualbox.org/ticket/3444

Source: VUPEN
Type: Patch, Vendor Advisory
ADV-2009-0674

Source: CONFIRM
Type: UNKNOWN
https://bugs.gentoo.org/show_bug.cgi?id=260331

Source: XF
Type: UNKNOWN
xvmvirtualbox-unspecified-priv-escalation(49193)

Source: XF
Type: UNKNOWN
xvmvirtualbox-unspecified-priv-escalation(49193)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:sun:xvm_virtualbox:2.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:sun:xvm_virtualbox:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:sun:xvm_virtualbox:2.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:sun:xvm_virtualbox:2.0.6r39760:*:*:*:*:*:*:*
  • OR cpe:/a:sun:xvm_virtualbox:2.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:sun:xvm_virtualbox:2.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:sun:xvm_virtualbox:2.1.4r42893:*:*:*:*:*:*:*
  • AND
  • cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:sun:xvm_virtualbox:2.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:sun:xvm_virtualbox:2.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:sun:xvm_virtualbox:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:sun:xvm_virtualbox:2.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:sun:xvm_virtualbox:2.0.6r39760:*:*:*:*:*:*:*
  • OR cpe:/a:sun:xvm_virtualbox:2.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:sun:xvm_virtualbox:2.1.4r42893:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sun xvm virtualbox 2.0.0
    sun xvm virtualbox 2.0.2
    sun xvm virtualbox 2.0.4
    sun xvm virtualbox 2.0.6r39760
    sun xvm virtualbox 2.1.0
    sun xvm virtualbox 2.1.2
    sun xvm virtualbox 2.1.4r42893
    linux linux kernel *
    sun xvm virtualbox 2.0.0
    sun xvm virtualbox 2.1.0
    sun xvm virtualbox 2.0.2
    sun xvm virtualbox 2.0.4
    sun xvm virtualbox 2.0.6r39760
    sun xvm virtualbox 2.1.2
    sun xvm virtualbox 2.1.4r42893