CVE-2012-3386

The "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:automake:1.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.10.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.4:p2:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.10:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.4:p1:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.7.8:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.9.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.8:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.11.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:*:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.11.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.10.0.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.7.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.7.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.6.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.7.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.9.6:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.4:p6:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.11.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.10.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.8.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.9.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.8.5:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.8.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.7.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.11.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.9:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.9.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.7.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.7.7:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.12.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.4:p3:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.7.2:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.4:p4:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.9.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.12:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.10.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.9.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.8.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.4:p5:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.8.4:*:*:*:*:*:*:*
cpe:2.3:a:gnu:automake:1.7.9:*:*:*:*:*:*:*

Information

Published : 2012-08-07 14:55

Updated : 2023-02-12 20:33


NVD link : CVE-2012-3386

Mitre link : CVE-2012-3386


JSON object : View

CWE
CWE-264

Permissions, Privileges, and Access Controls

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Advertisement

dedicated server usa

Products Affected

gnu

  • automake