CVE Vulnerabilities

CVE-2009-3736

Published: Nov 29, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
6.2 MODERATE
AV:L/AC:H/Au:N/C:C/I:C/A:C
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

Affected Software

NameVendorStart VersionEnd Version
LibtoolGnu1.5 (including)1.5 (including)
LibtoolGnu1.5.2 (including)1.5.2 (including)
LibtoolGnu1.5.4 (including)1.5.4 (including)
LibtoolGnu1.5.6 (including)1.5.6 (including)
LibtoolGnu1.5.8 (including)1.5.8 (including)
LibtoolGnu1.5.10 (including)1.5.10 (including)
LibtoolGnu1.5.12 (including)1.5.12 (including)
LibtoolGnu1.5.14 (including)1.5.14 (including)
LibtoolGnu1.5.16 (including)1.5.16 (including)
LibtoolGnu1.5.18 (including)1.5.18 (including)
LibtoolGnu1.5.20 (including)1.5.20 (including)
LibtoolGnu1.5.22 (including)1.5.22 (including)
LibtoolGnu1.5.24 (including)1.5.24 (including)
LibtoolGnu1.5.26 (including)1.5.26 (including)
LibtoolGnu2.2.6a (including)2.2.6a (including)
Red Hat Enterprise Linux 3RedHatlibtool-0:1.4.3-7*
Red Hat Enterprise Linux 3RedHatgcc-0:3.2.3-60*
Red Hat Enterprise Linux 4RedHatlibtool-0:1.5.6-5.el4_8*
Red Hat Enterprise Linux 4RedHatgcc-0:3.4.6-11.el4_8.1*
Red Hat Enterprise Linux 4RedHatgcc4-0:4.1.2-44.EL4_8.1*
Red Hat Enterprise Linux 5RedHatlibtool-0:1.5.22-7.el5_4*
Red Hat Enterprise Linux 5RedHatgcc-0:4.1.2-46.el5_4.2*
LibtoolUbuntudapper*
LibtoolUbuntuhardy*
LibtoolUbuntuintrepid*
LibtoolUbuntujaunty*
LibtoolUbuntukarmic*
LibtoolUbuntuupstream*

References