Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-3736

Опубликовано: 16 нояб. 2009
Источник: redhat
CVSS2: 6.2
EPSS Низкий

Описание

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Application Stack v2 for Enterprise LinuxunixODBCWill not fix
Red Hat Enterprise Linux 4guileNot affected
Red Hat Enterprise Linux 5gcc44Will not fix
Red Hat Enterprise Linux 5guileWill not fix
Red Hat Enterprise Linux 6guileWill not fix
Red Hat Enterprise Linux 6libtoolNot affected
Red Hat Enterprise Linux 3libtoolFixedRHSA-2009:164608.12.2009
Red Hat Enterprise Linux 3gccFixedRHSA-2010:003913.01.2010
Red Hat Enterprise Linux 4libtoolFixedRHSA-2009:164608.12.2009
Red Hat Enterprise Linux 4gccFixedRHSA-2010:003913.01.2010

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=537941libtool: libltdl may load and execute code from a library in the current directory

EPSS

Процентиль: 28%
0.00097
Низкий

6.2 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 15 лет назад

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

nvd
больше 15 лет назад

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

debian
больше 15 лет назад

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as us ...

github
около 3 лет назад

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

oracle-oval
больше 15 лет назад

ELSA-2010-0039: gcc and gcc4 security update (MODERATE)

EPSS

Процентиль: 28%
0.00097
Низкий

6.2 Medium

CVSS2