4.4
CVSSv2

CVE-2012-3386

Published: 07/08/2012 Updated: 13/02/2023
CVSS v2 Base Score: 4.4 | Impact Score: 6.4 | Exploitability Score: 3.4
VMScore: 392
Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The "make distcheck" rule in GNU Automake prior to 1.11.6 and 1.12.x prior to 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu automake 1.5

gnu automake 1.10.1

gnu automake 1.4

gnu automake 1.10

gnu automake 1.7.8

gnu automake 1.9.2

gnu automake 1.8

gnu automake 1.11.1

gnu automake 1.3

gnu automake

gnu automake 1.6

gnu automake 1.6.1

gnu automake 1.11.4

gnu automake 1.2

gnu automake 1.10.0.3

gnu automake 1.7.5

gnu automake 1.7.6

gnu automake 1.6.2

gnu automake 1.7

gnu automake 1.7.3

gnu automake 1.9.6

gnu automake 1.11.3

gnu automake 1.10.2

gnu automake 1.8.2

gnu automake 1.9.5

gnu automake 1.8.5

gnu automake 1.8.3

gnu automake 1.7.1

gnu automake 1.11.2

gnu automake 1.9

gnu automake 1.9.1

gnu automake 1.7.4

gnu automake 1.7.7

gnu automake 1.12.1

gnu automake 1.7.2

gnu automake 1.9.3

gnu automake 1.0

gnu automake 1.12

gnu automake 1.6.3

gnu automake 1.10.3

gnu automake 1.9.4

gnu automake 1.8.1

gnu automake 1.8.4

gnu automake 1.7.9

Vendor Advisories

Synopsis Low: automake security update Type/Severity Security Advisory: Low Topic An updated automake package that fixes one security issue is now availablefor Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having lowsecurity impact A Common Vulnerability Scoring Sys ...
Debian Bug report logs - #681097 CVE-2012-3386: Information disclosure Package: automake; Maintainer for automake is Eric Dorland <eric@debianorg>; Source for automake is src:automake-116 (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Tue, 10 Jul 2012 16:00:01 UTC Severity: ...
It was found that the distcheck rule in Automake-generated Makefiles made a directory world-writable when preparing source archives If a malicious, local user could access this directory, they could execute arbitrary code with the privileges of the user running "make distcheck" ...