[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2010:0039 -- centos 5 i386 gcc

ID: oval:org.secpod.oval:def:201807Date: (C)2012-01-31   (M)2021-11-24
Class: PATCHFamily: unix




The gcc and gcc4 packages include, among others, C, C++, and Java GNU compilers and related support libraries. libgcj contains a copy of GNU Libtool"s libltdl library. A flaw was found in the way GNU Libtool"s libltdl library looked for libraries to load. It was possible for libltdl to load a malicious library from the current working directory. In certain configurations, if a local attacker is able to trick a local user into running a Java application from within an attacker-controlled directory containing a malicious library or module, the attacker could possibly execute arbitrary code with the privileges of the user running the Java application. All gcc and gcc4 users should upgrade to these updated packages, which contain a backported patch to correct this issue. All running Java applications using libgcj must be restarted for this update to take effect.

Platform:
CentOS 5
Product:
gcc
Reference:
CESA-2010:0039
CVE-2009-3736
CVE    1
CVE-2009-3736
CPE    2
cpe:/a:gnu:gcc
cpe:/o:centos:centos:5

© SecPod Technologies