CVE-2009-4029

The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:automake:1.10.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.11.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:branch:1-9:*:*:*:*:*:*

History

No history.

Information

Published : 2009-12-20 02:30

Updated : 2023-12-10 11:03


NVD link : CVE-2009-4029

Mitre link : CVE-2009-4029

CVE.ORG link : CVE-2009-4029


JSON object : View

Products Affected

gnu

  • automake
CWE
CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')