CVE Vulnerabilities

CVE-2012-3386

Published: Aug 07, 2012 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

The make distcheck rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.

Affected Software

Name Vendor Start Version End Version
Automake Gnu * 1.11.5 (including)
Automake Gnu 1.0 (including) 1.0 (including)
Automake Gnu 1.2 (including) 1.2 (including)
Automake Gnu 1.3 (including) 1.3 (including)
Automake Gnu 1.4 (including) 1.4 (including)
Automake Gnu 1.4-p1 (including) 1.4-p1 (including)
Automake Gnu 1.4-p2 (including) 1.4-p2 (including)
Automake Gnu 1.4-p3 (including) 1.4-p3 (including)
Automake Gnu 1.4-p4 (including) 1.4-p4 (including)
Automake Gnu 1.4-p5 (including) 1.4-p5 (including)
Automake Gnu 1.4-p6 (including) 1.4-p6 (including)
Automake Gnu 1.5 (including) 1.5 (including)
Automake Gnu 1.6 (including) 1.6 (including)
Automake Gnu 1.6.1 (including) 1.6.1 (including)
Automake Gnu 1.6.2 (including) 1.6.2 (including)
Automake Gnu 1.6.3 (including) 1.6.3 (including)
Automake Gnu 1.7 (including) 1.7 (including)
Automake Gnu 1.7.1 (including) 1.7.1 (including)
Automake Gnu 1.7.2 (including) 1.7.2 (including)
Automake Gnu 1.7.3 (including) 1.7.3 (including)
Automake Gnu 1.7.4 (including) 1.7.4 (including)
Automake Gnu 1.7.5 (including) 1.7.5 (including)
Automake Gnu 1.7.6 (including) 1.7.6 (including)
Automake Gnu 1.7.7 (including) 1.7.7 (including)
Automake Gnu 1.7.8 (including) 1.7.8 (including)
Automake Gnu 1.7.9 (including) 1.7.9 (including)
Automake Gnu 1.8 (including) 1.8 (including)
Automake Gnu 1.8.1 (including) 1.8.1 (including)
Automake Gnu 1.8.2 (including) 1.8.2 (including)
Automake Gnu 1.8.3 (including) 1.8.3 (including)
Automake Gnu 1.8.4 (including) 1.8.4 (including)
Automake Gnu 1.8.5 (including) 1.8.5 (including)
Automake Gnu 1.9 (including) 1.9 (including)
Automake Gnu 1.9.1 (including) 1.9.1 (including)
Automake Gnu 1.9.2 (including) 1.9.2 (including)
Automake Gnu 1.9.3 (including) 1.9.3 (including)
Automake Gnu 1.9.4 (including) 1.9.4 (including)
Automake Gnu 1.9.5 (including) 1.9.5 (including)
Automake Gnu 1.9.6 (including) 1.9.6 (including)
Automake Gnu 1.10 (including) 1.10 (including)
Automake Gnu 1.10.0.3 (including) 1.10.0.3 (including)
Automake Gnu 1.10.1 (including) 1.10.1 (including)
Automake Gnu 1.10.2 (including) 1.10.2 (including)
Automake Gnu 1.10.3 (including) 1.10.3 (including)
Automake Gnu 1.11.1 (including) 1.11.1 (including)
Automake Gnu 1.11.2 (including) 1.11.2 (including)
Automake Gnu 1.11.3 (including) 1.11.3 (including)
Automake Gnu 1.11.4 (including) 1.11.4 (including)
Automake Gnu 1.12 (including) 1.12 (including)
Automake Gnu 1.12.1 (including) 1.12.1 (including)
Red Hat Enterprise Linux 5 RedHat automake-0:1.9.6-3.el5 *
Red Hat Enterprise Linux 6 RedHat automake-0:1.11.1-4.el6 *
Automake Ubuntu hardy *
Automake Ubuntu lucid *
Automake Ubuntu natty *
Automake Ubuntu oneiric *
Automake Ubuntu precise *
Automake Ubuntu quantal *
Automake Ubuntu raring *
Automake Ubuntu saucy *
Automake Ubuntu trusty *
Automake Ubuntu utopic *
Automake Ubuntu vivid *

References