PT-2009-6708 · Gnu+1 · Libstdc++-Devel+14

Published

1970-01-01

·

Updated

2024-06-15

·

CVE-2009-3736

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libtool versions 1.4.3 through 1.5.22 libtool-libs versions 1.4.3 through 1.5.6 libltdl3-dev version 1.5.x libltdl3 version 1.5.x gcc version 4.1.2 gcc-c++ version 4.1.2 gcc-gfortran version 4.1.2 gcc-gnat version 4.1.2 gcc-java version 4.1.2 gcc-objc version 4.1.2 gcc-objc++ version 4.1.2 libgcj-devel version 4.1.2 libgcj-src version 4.1.2 libmudflap-devel version 4.1.2 libstdc++-devel version 4.1.2
Description The issue allows local users to gain privileges via a Trojan horse file, potentially leading to a breach of confidentiality, integrity, and availability of protected information. This can be achieved by exploiting a vulnerability in the ltdl.c file in libltdl, which attempts to open a .la file in the current working directory. The estimated number of potentially affected devices worldwide is not provided. There is no information about real-world incidents where this issue was exploited.
Recommendations For libtool versions 1.4.3 through 1.5.22, consider disabling the vulnerable ltdl.c file until a patch is available. For libtool-libs versions 1.4.3 through 1.5.6, restrict access to the vulnerable module to minimize the risk of exploitation. For libltdl3-dev and libltdl3 version 1.5.x, avoid using the vulnerable ltdl.c file in the affected API endpoint until the issue is resolved. For gcc and its variants (gcc-c++, gcc-gfortran, gcc-gnat, gcc-java, gcc-objc, gcc-objc++), consider updating to a newer version that contains a fix for this issue. For libgcj-devel, libgcj-src, libmudflap-devel, and libstdc++-devel, restrict access to the vulnerable components to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03277
BDU:2015-03278
BDU:2015-06742
BDU:2015-06744
BDU:2015-06746
BDU:2015-06748
BDU:2015-06750
BDU:2015-06751
BDU:2015-06753
BDU:2015-06796
BDU:2015-06797
BDU:2015-06803
BDU:2015-06810
BDU:2015-06811
BDU:2015-06812
BDU:2015-06813
BDU:2015-06814
BDU:2015-06815
BDU:2015-06816
BDU:2015-06817
BDU:2015-08554
BDU:2015-08555
BDU:2015-08556
BDU:2015-08557
BDU:2015-08558
BDU:2015-08559
BDU:2015-08560
CVE-2009-3736
DSA-1958-1
OPENSUSE-SU-2024:10168-1
OPENSUSE-SU-2024:10505-1
RHSA-2009:1646
RHSA-2009_1646
RHSA-2010:0039
RHSA-2010_0039

Affected Products

Red Hat
Gcc
Gcc-C++
Gcc-Gfortran
Gcc-Gnat
Gcc-Java
Gcc-Objc
Libgcj-Devel
Libgcj-Src
Libltdl3
Libltdl3-Dev
Libmudflap-Devel
Libstdc++-Devel
Libtool
Libtool-Libs