- update to 2.2.6b, fixes CVE-2009-3736: libltdl may load and execute code

from a library in the current directory
This commit is contained in:
Karsten Hopp 2009-12-02 11:20:28 +00:00
parent 4fe6c734d0
commit d71ca8096f
2 changed files with 7 additions and 3 deletions

View File

@ -3,10 +3,10 @@
Summary: The GNU Portable Library Tool
Name: libtool
Version: 2.2.6
Release: 15%{?dist}
Release: 16%{?dist}
License: GPLv2+ and LGPLv2+ and GFDL
Group: Development/Tools
Source: http://ftp.gnu.org/gnu/libtool/libtool-%{version}a.tar.lzma
Source: http://ftp.gnu.org/gnu/libtool/libtool-%{version}b.tar.lzma
Patch0: libtool-2.2.6a-rpath.patch
URL: http://www.gnu.org/software/libtool/
BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-%(%{__id_u} -n)
@ -142,6 +142,10 @@ fi
%changelog
* Wed Dec 02 2009 Karsten Hopp <karsten@redhat.com> 2.2.6-16
- update to 2.2.6b, fixes CVE-2009-3736:
libltdl may load and execute code from a library in the current directory
* Mon Oct 19 2009 Jakub Jelinek <jakub@redhat.com> 2.2.6-15
- Rebuild for gcc 4.4.2

View File

@ -1 +1 @@
b121e4848cc53fdd69e796aed73b9ccf libtool-2.2.6a.tar.lzma
a4b36980765003b47dd75ac9429f4f11 libtool-2.2.6b.tar.lzma