Unrated severityNVD Advisory· Published Nov 29, 2009· Updated Apr 23, 2026
CVE-2009-3736
CVE-2009-3736
Description
ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
Affected products
15cpe:2.3:a:gnu:libtool:1.5:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:gnu:libtool:1.5:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:1.5.10:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:1.5.12:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:1.5.14:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:1.5.16:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:1.5.18:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:1.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:1.5.20:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:1.5.22:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:1.5.24:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:1.5.26:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:1.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:1.5.6:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:1.5.8:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:libtool:2.2.6a:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
38- ftp.gnu.org/gnu/libtool/libtool-2.2.6a-2.2.6b.diff.gznvdPatch
- git.savannah.gnu.org/cgit/libtool.git/commit/nvdPatch
- lists.gnu.org/archive/html/libtool/2009-11/msg00059.htmlnvdPatch
- lists.gnu.org/archive/html/libtool/2009-11/msg00065.htmlnvdPatch
- www.securityfocus.com/bid/37128nvdPatch
- bugzilla.redhat.com/show_bug.cginvdPatch
- secunia.com/advisories/37414nvdVendor Advisory
- secunia.com/advisories/37489nvdVendor Advisory
- hamlib.svn.sourceforge.net/viewvc/hamlib/trunk/libltdl/Makefile.amnvd
- kb.juniper.net/InfoCenter/indexnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-February/035133.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2010-February/035168.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-March/054656.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-March/054915.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2011-March/054921.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlnvd
- secunia.com/advisories/37997nvd
- secunia.com/advisories/38190nvd
- secunia.com/advisories/38577nvd
- secunia.com/advisories/38617nvd
- secunia.com/advisories/38696nvd
- secunia.com/advisories/38915nvd
- secunia.com/advisories/39299nvd
- secunia.com/advisories/39347nvd
- secunia.com/advisories/43617nvd
- secunia.com/advisories/55721nvd
- security.gentoo.org/glsa/glsa-201311-10.xmlnvd
- support.avaya.com/css/P8/documents/100074869nvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.mandriva.com/security/advisoriesnvd
- www.redhat.com/support/errata/RHSA-2010-0039.htmlnvd
- www.vupen.com/english/advisories/2011/0574nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11687nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6951nvd
- rhn.redhat.com/errata/RHSA-2010-0095.htmlnvd
- www.redhat.com/archives/fedora-package-announce/2009-December/msg01512.htmlnvd
News mentions
0No linked articles in our index yet.