First published: Tue Dec 08 2009(Updated: )
GNU Libtool is a set of shell scripts which automatically configure UNIX,<br>Linux, and similar operating systems to generically build shared libraries.<br>A flaw was found in the way GNU Libtool's libltdl library looked for<br>modules to load. It was possible for libltdl to load and run modules from<br>an arbitrary library in the current working directory. If a local attacker<br>could trick a local user into running an application (which uses libltdl)<br>from an attacker-controlled directory containing a malicious Libtool<br>control file (.la), the attacker could possibly execute arbitrary code with<br>the privileges of the user running the application. (CVE-2009-3736)<br>All libtool users should upgrade to these updated packages, which contain<br>a backported patch to correct this issue. After installing the updated<br>packages, applications using the libltdl library must be restarted for the<br>update to take effect.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/libtool | <1.5.22-7.el5_4 | 1.5.22-7.el5_4 |
redhat/libtool | <1.5.22-7.el5_4 | 1.5.22-7.el5_4 |
redhat/libtool-ltdl | <1.5.22-7.el5_4 | 1.5.22-7.el5_4 |
redhat/libtool-ltdl | <1.5.22-7.el5_4 | 1.5.22-7.el5_4 |
redhat/libtool-ltdl-devel | <1.5.22-7.el5_4 | 1.5.22-7.el5_4 |
redhat/libtool-ltdl-devel | <1.5.22-7.el5_4 | 1.5.22-7.el5_4 |
redhat/libtool | <1.5.6-5.el4_8 | 1.5.6-5.el4_8 |
redhat/libtool | <1.5.6-5.el4_8 | 1.5.6-5.el4_8 |
redhat/libtool-libs | <1.5.6-5.el4_8 | 1.5.6-5.el4_8 |
redhat/libtool-libs | <1.5.6-5.el4_8 | 1.5.6-5.el4_8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2009:1646 is classified as moderate.
To fix RHSA-2009:1646, update the affected packages to version 1.5.22-7.el5_4 or later for Red Hat Enterprise Linux 5.
The affected packages in RHSA-2009:1646 include libtool, libtool-ltdl, and libtool-ltdl-devel.
Yes, you should upgrade to version 1.5.22-7.el5_4 for the affected packages.
RHSA-2009:1646 is related to a flaw in how GNU Libtool's libltdl library locates and loads modules.