VYPR
Unrated severityNVD Advisory· Published Nov 29, 2009· Updated Apr 23, 2026

CVE-2009-3736

CVE-2009-3736

Description

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

Affected products

15
  • GNU/Libtool15 versions
    cpe:2.3:a:gnu:libtool:1.5:*:*:*:*:*:*:*+ 14 more
    • cpe:2.3:a:gnu:libtool:1.5:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:1.5.10:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:1.5.12:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:1.5.14:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:1.5.16:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:1.5.18:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:1.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:1.5.20:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:1.5.22:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:1.5.24:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:1.5.26:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:1.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:1.5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:1.5.8:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:libtool:2.2.6a:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

38

News mentions

0

No linked articles in our index yet.