Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51332
Category:Conectiva Local Security Checks
Title:Conectiva Security Advisory CLA-2004:811
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory CLA-2004:811.

GNU libtool consists of a set of shell scripts used to build shared
libraries.

Joseph S. Myers and Stefan Nordhausen independently found[1,2] a
vulnerability[3] in the way the ltmain.sh script (which is part of
the libtool package) creates temporary directories for its use.

A local attacker could exploit this vulnerability to change/delete
arbitrary files in the system on behalf of the user who is calling
the script.

The vulnerability has been fixed in the 1.5.2 version of libtool.
This update keeps the original versions distributed with Conectiva
Linux, fixing the vulnerability by using mktemp to securely create
the directories.


Solution:
The apt tool can be used to perform RPM package upgrades
by running 'apt-get update' followed by 'apt-get upgrade'

http://www.securityfocus.com/archive/1/352333
http://www.geocrawler.com/mail/msg.php3?msg_id=3438808&list=405
http://www.securityfocus.com/bid/9530
http://www.securityspace.com/smysecure/catid.html?in=CLA-2004:811
http://distro.conectiva.com.br/atualizacoes/index.php?id=a&anuncio=002004

Risk factor : High

CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.