CVE-2009-4029

Description

The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete.

Risk Information

Base Score
7.7
MODERATE
Vector
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
0.688

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2010:0321) Low: automake security update automake15-1.5-16.el5.2.noarch.rpmLinux
(RHSA-2010:0321) Low: automake security update automake16-1.6.3-8.el5.1.noarch.rpmLinux
(RHSA-2010:0321) Low: automake security update automake17-1.7.9-7.el5.2.noarch.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234