CVE-2009-4135

The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:gnu:coreutils:5.2.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:5.91:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:5.92:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:5.93:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:5.94:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:5.95:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:5.96:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:5.97:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:6.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:6.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:6.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:6.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:6.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:6.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:6.8:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:6.9:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:6.10:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:6.11:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:6.12:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:7.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:7.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:7.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:7.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:7.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:7.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:coreutils:8.1:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:12:*:*:*:*:*:*:*

History

13 Feb 2023, 02:20

Type Values Removed Values Added
References
  • {'url': 'http://www.mail-archive.com/bug-coreutils@gnu.org/msg18787.html', 'name': '[bug-coreutils] 20091209 [PATCH] doc: NEWS: mention the "make distcheck" vulnerability', 'tags': ['Mailing List', 'Patch'], 'refsource': 'MLIST'}
  • {'url': 'http://www.mail-archive.com/bug-coreutils@gnu.org/msg18779.html', 'name': '[bug-coreutils] 20091208 Re: build: distcheck: do not leave a $TMPDIR/coreutils directory behind', 'tags': ['Mailing List', 'Patch'], 'refsource': 'MLIST'}
  • (MISC) http://www.mail-archive.com/bug-coreutils%40gnu.org/msg18787.html -
  • (MISC) http://www.mail-archive.com/bug-coreutils%40gnu.org/msg18779.html -

Information

Published : 2009-12-11 16:30

Updated : 2023-12-10 10:51


NVD link : CVE-2009-4135

Mitre link : CVE-2009-4135

CVE.ORG link : CVE-2009-4135


JSON object : View

Products Affected

fedoraproject

  • fedora

canonical

  • ubuntu_linux

gnu

  • coreutils
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')