Bugtraq mailing list archives
Re: Symlink Vulnerability in GNU libtool <1.5.2
From: Stefan Nordhausen <deletethis.nordhaus () informatik hu-berlin de>
Date: Tue, 03 Feb 2004 12:21:41 +0100
I wrote:
If you want to stick with your old version of libtoolyou can easily fix this bug yourself. In "ltmain.in" [...] you should replace the line:
This fix will not work for the version of libtool that is distributed with SuSE Linux (checked on SuSE 8.2/9.0). SuSE modified the tempdir creation to use mktemp if available. As a result the patch mentioned above would break SuSE's libtool, so don't use it for your SuSE Linux! Unfortunately, the changes made by SuSE don't fix the vulnerability (they just make it a bit harder to exploit) so that it is still necessary to apply a bugfix. Regards Stefan --Don't open your eyes, you won't like what you see. The devils of truth steal the souls of the free. Don't open your eyes, take it from me. I have found, you can find happiness in slavery.
Trent Reznor
Current thread:
- Symlink Vulnerability in GNU libtool <1.5.2 Stefan Nordhausen (Feb 02)
- Re: Symlink Vulnerability in GNU libtool <1.5.2 Joseph S. Myers (Feb 03)
- Re: Symlink Vulnerability in GNU libtool <1.5.2 Scott James Remnant (Feb 04)
- Re: Symlink Vulnerability in GNU libtool <1.5.2 Stefan Nordhausen (Feb 05)
- Re: Symlink Vulnerability in GNU libtool <1.5.2 Stefan Nordhausen (Feb 03)
- Re: Symlink Vulnerability in GNU libtool <1.5.2 jsm (Feb 05)
- Re: Symlink Vulnerability in GNU libtool <1.5.2 Joseph S. Myers (Feb 03)