The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2009-12-20T02:00:00

Updated: 2018-10-10T18:57:01

Reserved: 2009-11-20T00:00:00


Link: CVE-2009-4029

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2009-12-20T02:30:00.483

Modified: 2018-10-10T19:48:09.267


Link: CVE-2009-4029

JSON object: View

cve-icon Redhat Information

No data.

CWE