CVE-2009-3736
CVE-2009-3736
ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
ftp://ftp.gnu.org/gnu/libtool/libtool-2.2.6a-2.2.6b.diff.gzhttp://git.savannah.gnu.org/cgit/libtool.git/commit/?h=branch-1-5&id=29b48580df75f0c5baa2962548a4c101ec7ed7echttp://hamlib.svn.sourceforge.net/viewvc/hamlib/trunk/libltdl/Makefile.am?revision=2841&view=markuphttp://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035133.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2010-February/035168.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/054656.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/054915.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/054921.htmlhttp://lists.gnu.org/archive/html/libtool/2009-11/msg00059.htmlhttp://lists.gnu.org/archive/html/libtool/2009-11/msg00065.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html