Vulnerability Description
The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Automake | 1.10.3 |
Related Weaknesses (CWE)
References
- http://lists.gnu.org/archive/html/automake-patches/2009-11/msg00017.htmlExploit
- http://lists.gnu.org/archive/html/automake/2009-12/msg00010.html
- http://lists.gnu.org/archive/html/automake/2009-12/msg00011.html
- http://lists.gnu.org/archive/html/automake/2009-12/msg00012.htmlPatch
- http://lists.gnu.org/archive/html/automake/2009-12/msg00013.html
- http://savannah.gnu.org/forum/forum.php?forum_id=6077
- http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021784.1-1
- http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0071
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:203
- http://www.securityfocus.com/archive/1/514526/100/0/threaded
- http://www.vupen.com/english/advisories/2009/3579
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://lists.gnu.org/archive/html/automake-patches/2009-11/msg00017.htmlExploit
- http://lists.gnu.org/archive/html/automake/2009-12/msg00010.html
- http://lists.gnu.org/archive/html/automake/2009-12/msg00011.html
FAQ
What is CVE-2009-4029?
CVE-2009-4029 is a vulnerability with a CVSS score of 4.4 (MEDIUM). The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign i...
How severe is CVE-2009-4029?
CVE-2009-4029 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-4029?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Automake.