The "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://lists.fedoraproject.org/pipermail/package-announce/2012-October/089187.html | vendor advisory |
http://www.mandriva.com/security/advisories?name=MDVSA-2012:103 | vendor advisory |
http://lists.opensuse.org/opensuse-updates/2012-11/msg00038.html | vendor advisory |
http://lists.fedoraproject.org/pipermail/package-announce/2012-September/087538.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2013-0526.html | vendor advisory |
https://lists.gnu.org/archive/html/automake/2012-07/msg00021.html | patch mailing list |
https://lists.gnu.org/archive/html/automake/2012-07/msg00022.html | patch mailing list |
https://lists.gnu.org/archive/html/automake/2012-07/msg00023.html | patch mailing list |
http://git.savannah.gnu.org/cgit/automake.git/commit/?id=784b3e6ccc7c72a1c95c340cbbe8897d6b689d76 | patch exploit |
http://lists.fedoraproject.org/pipermail/package-announce/2012-September/087665.html | vendor advisory |