Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-3736

Опубликовано: 29 нояб. 2009
Источник: debian
EPSS Низкий

Описание

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libtoolfixed2.2.6b-1package
artsnot-affectedpackage
bochsnot-affectedpackage
camservremovedpackage
camservno-dsalennypackage
camservno-dsaetchpackage
collectdfixed4.8.2-1package
collectdno-dsalennypackage
collectdno-dsaetchpackage
cvsntfixed2.5.04.3236-1.2package
cvsntno-dsaetchpackage
cvsntno-dsalennypackage
ggobifixed2.1.9~20091212-1package
ggobino-dsaetchpackage
ggobino-dsalennypackage
gnashfixed0.8.7-2package
gnashno-dsalennypackage
gnu-smalltalkfixed3.1-2package
gnu-smalltalkno-dsalennypackage
gnu-smalltalkno-dsaetchpackage
graphicsmagickfixed1.3.5-6package
graphicsmagickno-dsalennypackage
graphicsmagickno-dsaetchpackage
guile-1.6fixed1.6.8-7package
guile-1.6no-dsaetchpackage
guile-1.6no-dsalennypackage
hamlibfixed1.2.10-1package
hamlibfixed1.2.7.1-1+lenny1lennypackage
hamlibno-dsaetchpackage
herculesfixed3.06-1.2package
herculesno-dsalennypackage
herculesno-dsaetchpackage
jagsfixed1.0.4-1package
kdelibsnot-affectedpackage
libannodexremovedpackage
libannodexno-dsalennypackage
libannodexno-dsaetchpackage
libextractorfixed0.5.23+dfsg-4package
libextractorno-dsaetchpackage
libextractorno-dsalennypackage
libmcryptnot-affectedpackage
libtunepimpfixed0.5.3-7.3package
libtunepimpno-dsalennypackage
libtunepimpno-dsaetchpackage
mp4hfixed1.3.1-4.1package
mp4hno-dsaetchpackage
mp4hno-dsalennypackage
naimremovedpackage
naimno-dsalennypackage
naimno-dsaetchpackage
parser-mysqlfixed10.3-2package
pinballfixed0.3.1-11package
pinballno-dsalennypackage
pinballno-dsaetchpackage
redlandfixed1.0.10-1package
redlandnot-affectedetchpackage
redlandnot-affectedlennypackage
siproxdfixed1:0.8.1-1package
siproxdno-dsalennypackage
siproxdno-dsaetchpackage
skiremovedpackage
synfigfixed0.62.00-1package
synfigno-dsalennypackage
xmlsec1fixed1.2.14-1package
clamavfixed0.95+dfsg-1package
clamavno-dsalennypackage
clamavno-dsaetchpackage
imagemagickfixed6:6.2.3.1-1package
imagemagickno-dsalennypackage
imagemagickno-dsaetchpackage
hyprefixed2.4.0b-5package
hypreno-dsaetchpackage
hypreno-dsalennypackage
lamfixed7.1.2-1.6package
lamno-dsalennypackage
lamno-dsaetchpackage
openmpifixed1.3.3-4package
openmpino-dsalennypackage
openmpino-dsaetchpackage
parserfixed3.4.0-2package
pdshnot-affectedpackage
sdccfixed2.9.0-5package
sdccno-dsalennypackage
sdccno-dsaetchpackage
proftpd-dfsgnot-affectedpackage
babelfixed1.4.0.dfsg-5package
babelno-dsalennypackage
libpreludefixed0.9.14-2package
libpreludeno-dsaetchpackage
heartbeatfixed2.1.4-7package
graphvizfixed2.26.3-14package
graphvizfixed2.26.3-5+squeeze1squeezepackage

Примечания

  • requested camserv removal

  • Embedded code copy isn't used

  • users with write access can modify configuration to load new extensions, see #559837

  • the dlopened path is always below /usr/lib/heartbeat, which isn't under control of an attacker

  • From Squeeze onwards the system copy of ltdl is used, use the current version from Squeeze,

  • might've been fixed earlier

EPSS

Процентиль: 28%
0.00097
Низкий

Связанные уязвимости

ubuntu
больше 15 лет назад

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

redhat
больше 15 лет назад

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

nvd
больше 15 лет назад

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

github
около 3 лет назад

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

oracle-oval
больше 15 лет назад

ELSA-2010-0039: gcc and gcc4 security update (MODERATE)

EPSS

Процентиль: 28%
0.00097
Низкий