The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2009-12-20T02:00:00

Updated: 2024-08-07T06:45:50.920Z

Reserved: 2009-11-20T00:00:00

Link: CVE-2009-4029

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2009-12-20T02:30:00.483

Modified: 2018-10-10T19:48:09.267

Link: CVE-2009-4029

cve-icon Redhat

Severity : Low

Publid Date: 2009-12-08T00:00:00Z

Links: CVE-2009-4029 - Bugzilla