ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2009-11-29 13:07
Updated : 2017-09-19 01:29
NVD link : CVE-2009-3736
Mitre link : CVE-2009-3736
CVE.ORG link : CVE-2009-3736
JSON object : View
Products Affected
gnu
- libtool
CWE