Vulnerability in automake < 1.11.6 allows local privilege escalation
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-3386
The “make distcheck” rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.
(from redmine: issue id 1763, created on 2013-04-05, closed on 2013-04-17)
- Relations:
- parent #1762 (closed)
- Changesets:
- Revision 34b273c5 by Natanael Copa on 2013-04-12T14:49:40Z:
main/automake: security fix (CVE-2012-3386)
fixes #1763