CVE-2009-3736

NameCVE-2009-3736
Descriptionltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-1958-1
Debian Bugs559797, 559800, 559801, 559803, 559806, 559808, 559809, 559811, 559813, 559814, 559815, 559816, 559818, 559819, 559821, 559822, 559823, 559824, 559825, 559826, 559827, 559828, 559829, 559831, 559832, 559833, 559834, 559835, 559836, 559837, 559840, 559843, 559844, 559845, 702436

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
bochs (PTS)bookworm2.7+dfsg-4+deb12u1fixed
forky, sid, trixie3.0+dfsg-1fixed
clamav (PTS)bookworm1.4.3+dfsg-1~deb12u2fixed
trixie1.4.3+dfsg-1fixed
forky, sid1.4.6+dfsg-1fixed
collectd (PTS)bookworm5.12.0-14fixed
trixie5.12.0-26fixed
sid5.12.0-28fixed
ggobi (PTS)bookworm2.1.11-2fixed
graphicsmagick (PTS)bookworm, bookworm (security)1.4+really1.3.40-4+deb12u1fixed
trixie1.4+really1.3.45+hg17696-1fixed
forky, sid1.4+really1.3.48-1fixed
graphviz (PTS)bookworm2.42.2-7+deb12u1fixed
trixie2.42.4-3fixed
forky, sid14.1.2-1fixed
hamlib (PTS)bookworm4.5.4-1fixed
trixie4.6.2-1fixed
forky, sid4.7.2-2fixed
heartbeat (PTS)bookworm1:3.0.6-13fixed
trixie1:3.0.6-17fixed
forky, sid1:3.0.6-19fixed
hercules (PTS)bookworm3.13-7fixed
trixie3.13-8fixed
forky, sid3.13-9fixed
hypre (PTS)bookworm2.26.0-3fixed
trixie2.32.0-4fixed
forky, sid3.1.0-3fixed
imagemagick (PTS)bookworm8:6.9.11.60+dfsg-1.6+deb12u11fixed
bookworm (security)8:6.9.11.60+dfsg-1.6+deb12u13fixed
trixie8:7.1.1.43+dfsg1-1+deb13u10fixed
trixie (security)8:7.1.1.43+dfsg1-1+deb13u11fixed
forky, sid8:7.1.2.29+dfsg2-1fixed
jags (PTS)bookworm4.3.1-1fixed
trixie4.3.2-1fixed
forky, sid4.3.2-2fixed
lam (PTS)bookworm7.1.4-7fixed
trixie7.1.4-7.2fixed
forky, sid7.1.4-8fixed
libextractor (PTS)bookworm1:1.11-7fixed
trixie1:1.13-8fixed
forky, sid1:1.19-2fixed
libmcrypt (PTS)bookworm2.5.8-7fixed
forky, sid, trixie2.5.8-8fixed
libprelude (PTS)bookworm5.2.0-5fixed
sid5.2.0-5.6fixed
libtool (PTS)bookworm2.4.7-7~deb12u1fixed
trixie2.5.4-4fixed
forky, sid2.6.2-2fixed
mp4h (PTS)bookworm1.3.1-17fixed
trixie1.3.1-17.2fixed
forky, sid1.3.1-17.3fixed
openmpi (PTS)bookworm4.1.4-3fixed
trixie5.0.7-1fixed
forky5.0.10-1fixed
sid5.0.10-5fixed
parser (PTS)bookworm3.4.6-3fixed
trixie3.5.1-2fixed
forky, sid3.5.1-3fixed
parser-mysql (PTS)bookworm10.8-3fixed
forky, sid, trixie10.9-1fixed
pdsh (PTS)bookworm2.34-0.2fixed
trixie2.35-2fixed
forky, sid2.36-1fixed
pinball (PTS)bookworm0.3.20201218-4fixed
trixie0.3.20230219-3fixed
forky, sid0.3.20230219-6fixed
proftpd-dfsg (PTS)bookworm1.3.8+dfsg-4+deb12u5fixed
bookworm (security)1.3.8+dfsg-4+deb12u4fixed
trixie1.3.8.c+dfsg-4+deb13u2fixed
forky, sid1.3.9d~dfsg-1fixed
redland (PTS)bookworm1.0.17-3fixed
trixie1.0.17-4fixed
forky, sid1.0.17-10fixed
sdcc (PTS)bookworm4.2.0+dfsg-1fixed
trixie4.5.0+dfsg-1fixed
forky, sid4.5.0+dfsg-4fixed
synfig (PTS)bookworm1.5.1+dfsg-3fixed
forky, sid1.5.5+dfsg-2fixed
xmlsec1 (PTS)bookworm1.2.37-2fixed
trixie1.2.41-1fixed
forky, sid1.3.10-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
artssource(unstable)(not affected)
babelsource(unstable)1.4.0.dfsg-5low559843
bochssource(unstable)(not affected)
camservsource(unstable)(unfixed)low559800
clamavsource(unstable)0.95+dfsg-1low559832
collectdsource(unstable)4.8.2-1low559801
cvsntsource(unstable)2.5.04.3236-1.2low559803
ggobisource(unstable)2.1.9~20091212-1low559806
gnashsource(unstable)0.8.7-2low559808
gnu-smalltalksource(unstable)3.1-2low559809
graphicsmagicksource(unstable)1.3.5-6low559811
graphvizsourcesqueeze2.26.3-5+squeeze1
graphvizsource(unstable)2.26.3-14low702436
guile-1.6source(unstable)1.6.8-7low559813
hamlibsourcelenny1.2.7.1-1+lenny1
hamlibsource(unstable)1.2.10-1low559814
heartbeatsource(unstable)2.1.4-7unimportant559845
herculessource(unstable)3.06-1.2low559815
hypresource(unstable)2.4.0b-5low559834
imagemagicksource(unstable)6:6.2.3.1-1low559833
jagssource(unstable)1.0.4-1low559816
kdelibssource(unstable)(not affected)
lamsource(unstable)7.1.2-1.6low559835
libannodexsource(unstable)(unfixed)low559818
libextractorsource(unstable)0.5.23+dfsg-4low559819
libmcryptsource(unstable)(not affected)
libpreludesource(unstable)0.9.14-2low559844
libtoolsourceetch1.5.22-4+etch1DSA-1958-1
libtoolsourcelenny1.5.26-4+lenny1DSA-1958-1
libtoolsource(unstable)2.2.6b-1low559797
libtunepimpsource(unstable)0.5.3-7.3low559821
mp4hsource(unstable)1.3.1-4.1low559822
naimsource(unstable)(unfixed)low559823
openmpisource(unstable)1.3.3-4low559836
parsersource(unstable)3.4.0-2unimportant559837
parser-mysqlsource(unstable)10.3-2unimportant559824
pdshsource(unstable)(not affected)
pinballsource(unstable)0.3.1-11low559825
proftpd-dfsgsource(unstable)(not affected)
redlandsourceetch(not affected)
redlandsourcelenny(not affected)
redlandsource(unstable)1.0.10-1low559826
sdccsource(unstable)2.9.0-5low559840
siproxdsource(unstable)1:0.8.1-1low559827
skisource(unstable)(unfixed)low559828
synfigsource(unstable)0.62.00-1low559829
xmlsec1source(unstable)1.2.14-1unimportant559831

Notes

- arts <not-affected> (Uses absolute path to the sound backend)
- bochs <not-affected> (additional hardening in this package prevents this type of attack; bug #559799)
requested camserv removal
[lenny] - camserv <no-dsa> (Minor issue)
[etch] - camserv <no-dsa> (Minor issue)
[lenny] - collectd <no-dsa> (Minor issue)
[etch] - collectd <no-dsa> (Minor issue)
[etch] - cvsnt <no-dsa> (Minor issue)
[lenny] - cvsnt <no-dsa> (Minor issue)
[etch] - ggobi <no-dsa> (Minor issue)
[lenny] - ggobi <no-dsa> (Minor issue)
[lenny] - gnash <no-dsa> (Minor issue)
[lenny] - gnu-smalltalk <no-dsa> (Minor issue)
[etch] - gnu-smalltalk <no-dsa> (Minor issue)
[lenny] - graphicsmagick <no-dsa> (Minor issue, can be fixed along with later updates)
[etch] - graphicsmagick <no-dsa> (Minor issue, can be fixed along with later updates)
[etch] - guile-1.6 <no-dsa> (Minor issue)
[lenny] - guile-1.6 <no-dsa> (Minor issue)
[etch] - hamlib <no-dsa> (Minor issue)
[lenny] - hercules <no-dsa> (Minor issue)
[etch] - hercules <no-dsa> (Minor issue)
- kdelibs <not-affected> (dl_open open loads from fixed paths)
[lenny] - libannodex <no-dsa> (Minor issue)
[etch] - libannodex <no-dsa> (Minor issue)
[etch] - libextractor <no-dsa> (Minor issue)
[lenny] - libextractor <no-dsa> (Minor issue)
- libmcrypt <not-affected> (not included in any of the binary packages; bug #559820)
[lenny] - libtunepimp <no-dsa> (Minor issue)
[etch] - libtunepimp <no-dsa> (Minor issue)
[etch] - mp4h <no-dsa> (Minor issue)
[lenny] - mp4h <no-dsa> (Minor issue)
[lenny] - naim <no-dsa> (Minor issue)
[etch] - naim <no-dsa> (Minor issue)
[lenny] - pinball <no-dsa> (Minor issue)
[etch] - pinball <no-dsa> (Minor issue)
[etch] - redland <not-affected> (Versions prior to 1.0.9 don't use libtool/libltdl)
[lenny] - redland <not-affected> (Versions prior to 1.0.9 don't use libtool/libltdl)
[lenny] - siproxd <no-dsa> (Minor issue)
[etch] - siproxd <no-dsa> (Minor issue)
[lenny] - synfig <no-dsa> (Minor issue)
Embedded code copy isn't used
[lenny] - clamav <no-dsa> (Minor issue)
[etch] - clamav <no-dsa> (Minor issue)
[lenny] - imagemagick <no-dsa> (Minor issue)
[etch] - imagemagick <no-dsa> (Minor issue)
[etch] - hypre <no-dsa> (Minor issue)
[lenny] - hypre <no-dsa> (Minor issue)
[lenny] - lam <no-dsa> (Minor issue)
[etch] - lam <no-dsa> (Minor issue)
[lenny] - openmpi <no-dsa> (Minor issue)
[etch] - openmpi <no-dsa> (Minor issue)
users with write access can modify configuration to load new extensions, see #559837
- pdsh <not-affected> (Only loads from /usr/lib/pdsh, which is controlled by root)
[lenny] - sdcc <no-dsa> (Minor issue)
[etch] - sdcc <no-dsa> (Minor issue)
- proftpd-dfsg <not-affected> (Only loads from /usr/lib/proftpd)
[lenny] - babel <no-dsa> (Minor issue)
[etch] - libprelude <no-dsa> (Minor issue)
the dlopened path is always below /usr/lib/heartbeat, which isn't under control of an attacker
From Squeeze onwards the system copy of ltdl is used, use the current version from Squeeze,
might've been fixed earlier

Search for package or bug name: Reporting problems