StackPatch is liveSee product

Back to CVE digest
CVE-2009-3736 · cross-distro fix matrix

CVE-2009-3736: ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

Affects 3 Linux releases across 50 (distro × package) combinations.

Fix per ecosystem

Each block below is a distro release where CVE-2009-3736 has a known fix. Run the listed command on that distro to remediate.

Debian bullseye

Source: Debian Security Tracker

  • clamav→ fixed in0.95+dfsg-1urgency: low
    sudo apt-get install --only-upgrade -y clamav
  • collectd→ fixed in4.8.2-1urgency: low
    sudo apt-get install --only-upgrade -y collectd
  • ggobi→ fixed in2.1.9~20091212-1urgency: low
    sudo apt-get install --only-upgrade -y ggobi
  • gnu-smalltalk→ fixed in3.1-2urgency: low
    sudo apt-get install --only-upgrade -y gnu-smalltalk
  • graphicsmagick→ fixed in1.3.5-6urgency: low
    sudo apt-get install --only-upgrade -y graphicsmagick
  • graphviz→ fixed in2.26.3-14urgency: low
    sudo apt-get install --only-upgrade -y graphviz
  • hamlib→ fixed in1.2.10-1urgency: low
    sudo apt-get install --only-upgrade -y hamlib
  • heartbeat→ fixed in2.1.4-7urgency: unimportant
    sudo apt-get install --only-upgrade -y heartbeat
  • hercules→ fixed in3.06-1.2urgency: low
    sudo apt-get install --only-upgrade -y hercules
  • hypre→ fixed in2.4.0b-5urgency: low
    sudo apt-get install --only-upgrade -y hypre
  • imagemagick→ fixed in6:6.2.3.1-1urgency: low
    sudo apt-get install --only-upgrade -y imagemagick
  • jags→ fixed in1.0.4-1urgency: low
    sudo apt-get install --only-upgrade -y jags
  • lam→ fixed in7.1.2-1.6urgency: low
    sudo apt-get install --only-upgrade -y lam
  • libextractor→ fixed in0.5.23+dfsg-4urgency: low
    sudo apt-get install --only-upgrade -y libextractor
  • libprelude→ fixed in0.9.14-2urgency: low
    sudo apt-get install --only-upgrade -y libprelude
  • libtool→ fixed in2.2.6b-1urgency: low
    sudo apt-get install --only-upgrade -y libtool
  • mp4h→ fixed in1.3.1-4.1urgency: low
    sudo apt-get install --only-upgrade -y mp4h
  • openmpi→ fixed in1.3.3-4urgency: low
    sudo apt-get install --only-upgrade -y openmpi
  • parser→ fixed in3.4.0-2urgency: unimportant
    sudo apt-get install --only-upgrade -y parser
  • parser-mysql→ fixed in10.3-2urgency: unimportant
    sudo apt-get install --only-upgrade -y parser-mysql
  • pinball→ fixed in0.3.1-11urgency: low
    sudo apt-get install --only-upgrade -y pinball
  • redland→ fixed in1.0.10-1urgency: low
    sudo apt-get install --only-upgrade -y redland
  • sdcc→ fixed in2.9.0-5urgency: low
    sudo apt-get install --only-upgrade -y sdcc
  • synfig→ fixed in0.62.00-1urgency: low
    sudo apt-get install --only-upgrade -y synfig
  • xmlsec1→ fixed in1.2.14-1urgency: unimportant
    sudo apt-get install --only-upgrade -y xmlsec1

Debian bookworm

Source: Debian Security Tracker

  • clamav→ fixed in0.95+dfsg-1urgency: low
    sudo apt-get install --only-upgrade -y clamav
  • collectd→ fixed in4.8.2-1urgency: low
    sudo apt-get install --only-upgrade -y collectd
  • ggobi→ fixed in2.1.9~20091212-1urgency: low
    sudo apt-get install --only-upgrade -y ggobi
  • graphicsmagick→ fixed in1.3.5-6urgency: low
    sudo apt-get install --only-upgrade -y graphicsmagick
  • graphviz→ fixed in2.26.3-14urgency: low
    sudo apt-get install --only-upgrade -y graphviz
  • hamlib→ fixed in1.2.10-1urgency: low
    sudo apt-get install --only-upgrade -y hamlib
  • heartbeat→ fixed in2.1.4-7urgency: unimportant
    sudo apt-get install --only-upgrade -y heartbeat
  • hercules→ fixed in3.06-1.2urgency: low
    sudo apt-get install --only-upgrade -y hercules
  • hypre→ fixed in2.4.0b-5urgency: low
    sudo apt-get install --only-upgrade -y hypre
  • imagemagick→ fixed in6:6.2.3.1-1urgency: low
    sudo apt-get install --only-upgrade -y imagemagick
  • jags→ fixed in1.0.4-1urgency: low
    sudo apt-get install --only-upgrade -y jags
  • lam→ fixed in7.1.2-1.6urgency: low
    sudo apt-get install --only-upgrade -y lam
  • libextractor→ fixed in0.5.23+dfsg-4urgency: low
    sudo apt-get install --only-upgrade -y libextractor
  • libprelude→ fixed in0.9.14-2urgency: low
    sudo apt-get install --only-upgrade -y libprelude
  • libtool→ fixed in2.2.6b-1urgency: low
    sudo apt-get install --only-upgrade -y libtool
  • mp4h→ fixed in1.3.1-4.1urgency: low
    sudo apt-get install --only-upgrade -y mp4h
  • openmpi→ fixed in1.3.3-4urgency: low
    sudo apt-get install --only-upgrade -y openmpi
  • parser→ fixed in3.4.0-2urgency: unimportant
    sudo apt-get install --only-upgrade -y parser
  • parser-mysql→ fixed in10.3-2urgency: unimportant
    sudo apt-get install --only-upgrade -y parser-mysql
  • pinball→ fixed in0.3.1-11urgency: low
    sudo apt-get install --only-upgrade -y pinball
  • redland→ fixed in1.0.10-1urgency: low
    sudo apt-get install --only-upgrade -y redland
  • sdcc→ fixed in2.9.0-5urgency: low
    sudo apt-get install --only-upgrade -y sdcc
  • synfig→ fixed in0.62.00-1urgency: low
    sudo apt-get install --only-upgrade -y synfig
  • xmlsec1→ fixed in1.2.14-1urgency: unimportant
    sudo apt-get install --only-upgrade -y xmlsec1

Debian trixie

Source: Debian Security Tracker

  • clamav→ fixed in0.95+dfsg-1urgency: low
    sudo apt-get install --only-upgrade -y clamav
Are YOU affected by CVE-2009-3736?

5-second check on your actual server. Reads /etc/os-release, uname -r, and the distro's package manager; matches against this same cross-source index live.

curl https://mindsparkstack.com/scan.sh | bash
Continuous monitoring beats manual checking

CVE-2009-3736dropped silently in your distro's update channel. Every new CVE is the same story. StackPatch runs the matcher hourly against all 5 sources and emails the exact remediation when something new applies to one of your servers. $99 lifetime, 50 founder seats, 30-day refund.

See StackPatch ($99 lifetime)