Description
ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
Published: 2009-11-27
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1958-1 New libtool packages fix privilege escalation
EUVD EUVD EUVD-2009-3708 ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
References
Link Providers
ftp://ftp.gnu.org/gnu/libtool/libtool-2.2.6a-2.2.6b.diff.gz cve-icon cve-icon
http://git.savannah.gnu.org/cgit/libtool.git/commit/?h=branch-1-5&id=29b48580df75f0c5baa2962548a4c101ec7ed7ec cve-icon cve-icon
http://hamlib.svn.sourceforge.net/viewvc/hamlib/trunk/libltdl/Makefile.am?revision=2841&view=markup cve-icon cve-icon
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035133.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2010-February/035168.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054656.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054915.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2011-March/054921.html cve-icon cve-icon
http://lists.gnu.org/archive/html/libtool/2009-11/msg00059.html cve-icon cve-icon
http://lists.gnu.org/archive/html/libtool/2009-11/msg00065.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.html cve-icon cve-icon
http://secunia.com/advisories/37414 cve-icon cve-icon
http://secunia.com/advisories/37489 cve-icon cve-icon
http://secunia.com/advisories/37997 cve-icon cve-icon
http://secunia.com/advisories/38190 cve-icon cve-icon
http://secunia.com/advisories/38577 cve-icon cve-icon
http://secunia.com/advisories/38617 cve-icon cve-icon
http://secunia.com/advisories/38696 cve-icon cve-icon
http://secunia.com/advisories/38915 cve-icon cve-icon
http://secunia.com/advisories/39299 cve-icon cve-icon
http://secunia.com/advisories/39347 cve-icon cve-icon
http://secunia.com/advisories/43617 cve-icon cve-icon
http://secunia.com/advisories/55721 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-201311-10.xml cve-icon cve-icon
http://support.avaya.com/css/P8/documents/100074869 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2009:307 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2010:035 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2010:091 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2010:105 cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2010-0039.html cve-icon cve-icon
http://www.securityfocus.com/bid/37128 cve-icon cve-icon
http://www.vupen.com/english/advisories/2011/0574 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=537941 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2009-3736 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11687 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6951 cve-icon cve-icon
https://rhn.redhat.com/errata/RHSA-2010-0095.html cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2009-3736 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01512.html cve-icon cve-icon
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00097}

epss

{'score': 0.00123}


Subscriptions

Gnu Libtool
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2024-08-07T06:38:29.973Z

Reserved: 2009-10-22T00:00:00.000Z

Link: CVE-2009-3736

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2009-11-29T13:07:52.030

Modified: 2026-04-23T00:35:47.467

Link: CVE-2009-3736

cve-icon Redhat

Severity : Moderate

Publid Date: 2009-11-16T00:00:00Z

Links: CVE-2009-3736 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses