CVE-2009-3736
Last modified
CVE-2009-3736 is a vulnerability of currently unknown severity. ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Libtool | 1.5 |
| Gnu | Libtool | 1.5.2 |
| Gnu | Libtool | 1.5.4 |
| Gnu | Libtool | 1.5.6 |
| Gnu | Libtool | 1.5.8 |
| Gnu | Libtool | 1.5.10 |
| Gnu | Libtool | 1.5.12 |
| Gnu | Libtool | 1.5.14 |
| Gnu | Libtool | 1.5.16 |
| Gnu | Libtool | 1.5.18 |
| Gnu | Libtool | 1.5.20 |
| Gnu | Libtool | 1.5.22 |
| Gnu | Libtool | 1.5.24 |
| Gnu | Libtool | 1.5.26 |
| Gnu | Libtool | 2.2.6a |
References
- http://secunia.com/advisories/37414Vendor Advisory
- http://secunia.com/advisories/37489Vendor Advisory
- http://secunia.com/advisories/37414Vendor Advisory
- http://secunia.com/advisories/37489Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-3736?
How severe is CVE-2009-3736?
How do I fix CVE-2009-3736?
Are you affected by CVE-2009-3736?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
