VDB
CVE-2009-1754
CVE-2009-1754
PUBLISHED
CVSS 4.300000190734863 MEDIUM
The PackageManagerService class in services/java/com/android/server/PackageManagerService.java in Android 1.5 through 1.5 CRB42 does not properly check developer certificates during processing of sharedUserId requests at an application's installation time, which allows remote user-assisted attackers to access application data by creating a package that specifies a shared user ID with an arbitrary application.
EPSS 0.68% · 50.9th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
0.68%
50.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| android | 1.5 | |
| n/a | n/a | n/a |
Timeline
- May 26, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 12, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 6, 2023 EPSS Score
- May 29, 2023 EPSS Score
References
- 35090 vdb
- [oss-security] 20090522 [oCERT-2009-006] Android improper package verification when using shared uids mailing-list
- http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=5d6d773fab559fdc12e553d60d789f3991ac552c url
- http://www.ocert.org/advisories/ocert-2009-006.html url
- 20090522 [oCERT-2009-006] Android improper package verification when using shared uids mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2009-1754 advisory
- http://android.git.kernel.org/?p=platform/frameworks/base.git;a=commit;h=5d6d773fab559fdc12e553d60d789f3991ac552c url