VDB
CVE-2009-0606
CVE-2009-0606
PUBLISHED
CVSS 7.199999809265137 HIGH
The link_image function in linker/linker.c in the dynamic linker in Bionic in Open Handset Alliance Android 1.0 on the T-Mobile G1 phone does not properly handle file descriptors 0, 1, and 2 for a setgid program, which allows local users to create arbitrary files owned by certain groups, possibly a related issue to CVE-2002-0820.
EPSS 0.30% · 23.0th percentile
Risk Scores
CVSS 2.0
7.199999809265137
EPSS Score
0.30%
23.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openhandsetalliance | android_sdk | 1.0 |
| n/a | n/a | n/a |
Timeline
- Feb 17, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 5, 2023 EPSS Score
- May 28, 2023 EPSS Score