Vulnerabilidad en ltdl.c en libltdl en GNU Libtool (CVE-2009-3736)
Gravedad CVSS v2.0:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
29/11/2009
Última modificación:
09/04/2025
Descripción
ltdl.c en libltdl en GNU Libtool v1.5.x, y v2.2.6 anterior v2.2.6b, intenta abrir un archivo .la en el directorio de trabajo, lo que permite a usuarios locales obtener privilegios a través de un troyano.
Impacto
Puntuación base 2.0
6.90
Gravedad 2.0
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:gnu:libtool:1.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:1.5.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:1.5.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:1.5.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:1.5.8:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:1.5.10:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:1.5.12:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:1.5.14:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:1.5.16:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:1.5.18:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:1.5.20:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:1.5.22:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:1.5.24:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:1.5.26:*:*:*:*:*:*:* | ||
| cpe:2.3:a:gnu:libtool:2.2.6a:*:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- ftp://ftp.gnu.org/gnu/libtool/libtool-2.2.6a-2.2.6b.diff.gz
- http://git.savannah.gnu.org/cgit/libtool.git/commit/?h=branch-1-5&id=29b48580df75f0c5baa2962548a4c101ec7ed7ec
- http://hamlib.svn.sourceforge.net/viewvc/hamlib/trunk/libltdl/Makefile.am?revision=2841&view=markup
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035133.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035168.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054656.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054915.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054921.html
- http://lists.gnu.org/archive/html/libtool/2009-11/msg00059.html
- http://lists.gnu.org/archive/html/libtool/2009-11/msg00065.html
- http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html
- http://secunia.com/advisories/37414
- http://secunia.com/advisories/37489
- http://secunia.com/advisories/37997
- http://secunia.com/advisories/38190
- http://secunia.com/advisories/38577
- http://secunia.com/advisories/38617
- http://secunia.com/advisories/38696
- http://secunia.com/advisories/38915
- http://secunia.com/advisories/39299
- http://secunia.com/advisories/39347
- http://secunia.com/advisories/43617
- http://secunia.com/advisories/55721
- http://security.gentoo.org/glsa/glsa-201311-10.xml
- http://support.avaya.com/css/P8/documents/100074869
- http://www.mandriva.com/security/advisories?name=MDVSA-2009%3A307
- http://www.mandriva.com/security/advisories?name=MDVSA-2010%3A035
- http://www.mandriva.com/security/advisories?name=MDVSA-2010%3A091
- http://www.mandriva.com/security/advisories?name=MDVSA-2010%3A105
- http://www.redhat.com/support/errata/RHSA-2010-0039.html
- http://www.securityfocus.com/bid/37128
- http://www.vupen.com/english/advisories/2011/0574
- https://bugzilla.redhat.com/show_bug.cgi?id=537941
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11687
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6951
- https://rhn.redhat.com/errata/RHSA-2010-0095.html
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01512.html
- ftp://ftp.gnu.org/gnu/libtool/libtool-2.2.6a-2.2.6b.diff.gz
- http://git.savannah.gnu.org/cgit/libtool.git/commit/?h=branch-1-5&id=29b48580df75f0c5baa2962548a4c101ec7ed7ec
- http://hamlib.svn.sourceforge.net/viewvc/hamlib/trunk/libltdl/Makefile.am?revision=2841&view=markup
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035133.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035168.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054656.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054915.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054921.html
- http://lists.gnu.org/archive/html/libtool/2009-11/msg00059.html
- http://lists.gnu.org/archive/html/libtool/2009-11/msg00065.html
- http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html
- http://secunia.com/advisories/37414
- http://secunia.com/advisories/37489
- http://secunia.com/advisories/37997
- http://secunia.com/advisories/38190
- http://secunia.com/advisories/38577
- http://secunia.com/advisories/38617
- http://secunia.com/advisories/38696
- http://secunia.com/advisories/38915
- http://secunia.com/advisories/39299
- http://secunia.com/advisories/39347
- http://secunia.com/advisories/43617
- http://secunia.com/advisories/55721
- http://security.gentoo.org/glsa/glsa-201311-10.xml
- http://support.avaya.com/css/P8/documents/100074869
- http://www.mandriva.com/security/advisories?name=MDVSA-2009%3A307
- http://www.mandriva.com/security/advisories?name=MDVSA-2010%3A035
- http://www.mandriva.com/security/advisories?name=MDVSA-2010%3A091
- http://www.mandriva.com/security/advisories?name=MDVSA-2010%3A105
- http://www.redhat.com/support/errata/RHSA-2010-0039.html
- http://www.securityfocus.com/bid/37128
- http://www.vupen.com/english/advisories/2011/0574
- https://bugzilla.redhat.com/show_bug.cgi?id=537941
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11687
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6951
- https://rhn.redhat.com/errata/RHSA-2010-0095.html
- https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01512.html



