Revision Date: | 2013-04-29 | Version: | 13 | Title: | The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete. | Description: | The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete. | Family: | unix | Class: | vulnerability | Status: | ACCEPTED | Reference(s): | CVE-2009-4029
| Platform(s): | CentOS Linux 5 Oracle Linux 5 Red Hat Enterprise Linux 5
| Product(s): | | Definition Synopsis | RHEL5, CentOS5 or Oracle Linux 5 The operating system installed on the system is Red Hat Enterprise Linux 5
OR The operating system installed on the system is CentOS Linux 5.x
OR Oracle Linux 5.x
AND Configuration section
automake15 is earlier than 0:1.5-16.el5.2
OR automake is earlier than 0:1.9.6-2.3.el5
OR automake17 is earlier than 0:1.7.9-7.el5.2
OR automake16 is earlier than 0:1.6.3-8.el5.1
OR automake14 is earlier than 0:1.4p6-13.el5.1
|
|