First published: Mon Nov 16 2009(Updated: )
ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU libtool | =1.5.2 | |
GNU libtool | =1.5.24 | |
GNU libtool | =1.5 | |
GNU libtool | =1.5.8 | |
GNU libtool | =1.5.22 | |
GNU libtool | =1.5.6 | |
GNU libtool | =1.5.26 | |
GNU libtool | =1.5.18 | |
GNU libtool | =1.5.12 | |
GNU libtool | =2.2.6a | |
GNU libtool | =1.5.16 | |
GNU libtool | =1.5.10 | |
GNU libtool | =1.5.4 | |
GNU libtool | =1.5.20 | |
GNU libtool | =1.5.14 | |
redhat/libtool | <2.2.6 | 2.2.6 |
redhat/libtool | <0:1.5.6-5.el4_8 | 0:1.5.6-5.el4_8 |
redhat/gcc | <0:3.4.6-11.el4_8.1 | 0:3.4.6-11.el4_8.1 |
redhat/libtool | <0:1.5.22-7.el5_4 | 0:1.5.22-7.el5_4 |
redhat/gcc | <0:4.1.2-46.el5_4.2 | 0:4.1.2-46.el5_4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.