CVE-2009-0876

Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink attack, which preserves setuid/setgid bits on Linux, related to DT_RPATH:$ORIGIN.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
VendorProductVersion
sunxvm_virtualbox
2.0.0
sunxvm_virtualbox
2.0.2
sunxvm_virtualbox
2.0.4
sunxvm_virtualbox
2.0.6r39760:r39760
sunxvm_virtualbox
2.1.0
sunxvm_virtualbox
2.1.2
sunxvm_virtualbox
2.1.4r42893:r42893
𝑥
= Vulnerable software versions