[SECURITY] Fedora 12 Update: libtool-2.2.6-17.fc12

updates at fedoraproject.org updates at fedoraproject.org
Tue Dec 29 18:59:08 UTC 2009


--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-12562
2009-12-03 04:34:37
--------------------------------------------------------------------------------

Name        : libtool
Product     : Fedora 12
Version     : 2.2.6
Release     : 17.fc12
URL         : http://www.gnu.org/software/libtool/
Summary     : The GNU Portable Library Tool
Description :
GNU Libtool is a set of shell scripts which automatically configure UNIX and
UNIX-like systems to generically build shared libraries. Libtool provides a
consistent, portable interface which simplifies the process of using shared
libraries.

If you are developing programs which will use shared libraries, but do not use
the rest of the GNU Autotools (such as GNU Autoconf and GNU Automake), you
should install the libtool package.

The libtool package also includes all files needed to integrate the GNU
Portable Library Tool (libtool) and the GNU Libtool Dynamic Module Loader
(ltdl) into a package built using the GNU Autotools (including GNU Autoconf
and GNU Automake).

--------------------------------------------------------------------------------
Update Information:

libltdl may load and execute code from a library in the current directory.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Dec  2 2009 Karsten Hopp <karsten at redhat.com> 2.2.6-17
- fix directory name used in libtool tarball
* Wed Dec  2 2009 Karsten Hopp <karsten at redhat.com> 2.2.6-16
- update to 2.2.6b, fixes CVE-2009-3736:
  libltdl may load and execute code from a library in the current directory
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #537941 - CVE-2009-3736 libtool: libltdl may load and execute code from a library in the current directory
        https://bugzilla.redhat.com/show_bug.cgi?id=537941
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update libtool' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------




More information about the package-announce mailing list