Bug#559830: CVE-2009-3736 local privilege escalation

2009-12-12 Thread Michael Gilbert
On Sun, 6 Dec 2009 21:19:50 -0800 Steve Langasek wrote: > On Mon, Dec 07, 2009 at 12:04:18AM -0500, Michael Gilbert wrote: > > Package: unixodbc > > Severity: grave > > Tags: security > > > The following CVE (Common Vulnerabilities & Exposures) id was > > published for libtool. I have determined

Bug#559830: CVE-2009-3736 local privilege escalation

2009-12-06 Thread Michael Gilbert
On Sun, 6 Dec 2009 21:19:50 -0800 Steve Langasek wrote: > On Mon, Dec 07, 2009 at 12:04:18AM -0500, Michael Gilbert wrote: > > Package: unixodbc > > Severity: grave > > Tags: security > > > The following CVE (Common Vulnerabilities & Exposures) id was > > published for libtool. I have determined

Bug#559830: CVE-2009-3736 local privilege escalation

2009-12-06 Thread Michael Gilbert
Package: unixodbc Severity: grave Tags: security Hi, The following CVE (Common Vulnerabilities & Exposures) id was published for libtool. I have determined that this package embeds a vulnerable copy of the libtool source code. However, since this is a mass bug filing (due to so many packages em