CVE-2009-1754: Medium severity Google Android vulnerability
The PackageManagerService class in services/java/com/android/server/PackageManagerService.java in Android 1.5 through 1.5 CRB42 does not properly check developer certificates during processing of sharedUserId requests at an application's installation time, which allows remote user-assisted attackers to access application data by creating a package that specifies a shared user ID with an arbitrary application.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-1754?
CVE-2009-1754 is classified as a medium severity vulnerability due to improper certificate checks during app installation.
How do I fix CVE-2009-1754?
To fix CVE-2009-1754, upgrade to a newer version of Android that has addressed this vulnerability.
What versions of Android are affected by CVE-2009-1754?
CVE-2009-1754 affects Android versions 1.5 through 1.5 CRB42.
What are the potential impacts of CVE-2009-1754?
Exploitation of CVE-2009-1754 could allow remote user-assisted attackers to install malicious applications.
Is there a workaround for CVE-2009-1754?
There are no specific workarounds for CVE-2009-1754, and upgrading to a patched version is recommended.