CVE-2009-1754
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The PackageManagerService class in services/java/com/android/server/PackageManagerService.java in Android 1.5 through 1.5 CRB42 does not properly check developer certificates during processing of sharedUserId requests at an application's installation time, which allows remote user-assisted attackers to access application data by creating a package that specifies a shared user ID with an arbitrary application.
La clase PackageManagerService en services/java/com/android/server/PackageManagerService.java en Android v1.5 a v1.5 CRB42 no comprueba adecuadamente los certificados de desarrollador durante el procesado de las peticiones sharedUserId en el momento de instalar aplicaciones, lo que permite a atacantes remotos acceder a datos de la aplicación mediante la creación de un paquete que especifique un sharedUserId con una aplicación de su elección.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-05-21 CVE Reserved
- 2009-05-26 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://android.git.kernel.org/?p=platform/frameworks/base.git%3Ba=commit%3Bh=5d6d773fab559fdc12e553d60d789f3991ac552c | X_refsource_confirm | |
http://www.openwall.com/lists/oss-security/2009/05/22/14 | Mailing List |
|
http://www.securityfocus.com/archive/1/503770 | Mailing List | |
http://www.securityfocus.com/bid/35090 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.ocert.org/advisories/ocert-2009-006.html | 2023-11-07 |
URL | Date | SRC |
---|