CVE-2012-3386

NameCVE-2012-3386
DescriptionThe "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs681097

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
automake1.11 (PTS)buster1:1.11.6-5fixed
bookworm, bullseye, sid1:1.11.6-6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
automakesource(unstable)1:1.4-p6-13.1
automake1.10sourcesqueeze1:1.10.3-1+squeeze1
automake1.10source(unstable)1:1.10.3-3
automake1.11sourcesqueeze1:1.11.1-1+squeeze1
automake1.11source(unstable)1:1.11.6-1681097
automake1.7sourcesqueeze1.7.9-9.1+squeeze1
automake1.7source(unstable)1.7.9-10
automake1.9sourcesqueeze1.9.6+nogfdl-3.1+squeeze1
automake1.9source(unstable)1.9.6+nogfdl-4

Search for package or bug name: Reporting problems