ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
| Software | From | Fixed in |
|---|---|---|
| gnu / libtool | 1.5.2 | 1.5.2.x |
| gnu / libtool | 1.5.24 | 1.5.24.x |
| gnu / libtool | 1.5 | 1.5.x |
| gnu / libtool | 1.5.8 | 1.5.8.x |
| gnu / libtool | 1.5.22 | 1.5.22.x |
| gnu / libtool | 1.5.6 | 1.5.6.x |
| gnu / libtool | 1.5.26 | 1.5.26.x |
| gnu / libtool | 1.5.18 | 1.5.18.x |
| gnu / libtool | 1.5.12 | 1.5.12.x |
| gnu / libtool | 2.2.6a | 2.2.6a.x |
| gnu / libtool | 1.5.16 | 1.5.16.x |
| gnu / libtool | 1.5.10 | 1.5.10.x |
| gnu / libtool | 1.5.4 | 1.5.4.x |
| gnu / libtool | 1.5.20 | 1.5.20.x |
| gnu / libtool | 1.5.14 | 1.5.14.x |