Unrated severityNVD Advisory· Published Mar 12, 2009· Updated Apr 23, 2026
CVE-2009-0876
CVE-2009-0876
Description
Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink attack, which preserves setuid/setgid bits on Linux, related to DT_RPATH:$ORIGIN.
Affected products
7cpe:2.3:a:sun:xvm_virtualbox:2.0.0:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:sun:xvm_virtualbox:2.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:sun:xvm_virtualbox:2.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:sun:xvm_virtualbox:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:sun:xvm_virtualbox:2.0.6r39760:*:*:*:*:*:*:*
- cpe:2.3:a:sun:xvm_virtualbox:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:sun:xvm_virtualbox:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:sun:xvm_virtualbox:2.1.4r42893:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- sunsolve.sun.com/search/document.donvdPatchVendor Advisory
- www.virtualbox.org/ticket/3444nvdPatchVendor Advisory
- www.vupen.com/english/advisories/2009/0674nvdPatchVendor Advisory
- www.securityfocus.com/bid/34080nvdExploit
- secunia.com/advisories/34232nvdVendor Advisory
- osvdb.org/52580nvd
- www.openwall.com/lists/oss-security/2009/03/15/1nvd
- www.openwall.com/lists/oss-security/2009/03/17/2nvd
- www.securitytracker.com/idnvd
- bugs.gentoo.org/show_bug.cginvd
- exchange.xforce.ibmcloud.com/vulnerabilities/49193nvd
News mentions
0No linked articles in our index yet.