CVE-2012-3386

NameCVE-2012-3386
DescriptionThe "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
NVD severitymedium (attack range: local)
Debian Bugs681097
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
automake (PTS)wheezy, squeeze1:1.4-p6-13.1fixed
automake1.10 (PTS)squeeze1:1.10.3-1+squeeze1fixed
wheezy1:1.10.3-3fixed
automake1.11 (PTS)squeeze1:1.11.1-1+squeeze1fixed
wheezy1:1.11.6-1fixed
jessie, sid1:1.11.6-3fixed
automake1.7 (PTS)squeeze1.7.9-9.1+squeeze1fixed
automake1.9 (PTS)squeeze1.9.6+nogfdl-3.1+squeeze1fixed
wheezy1.9.6+nogfdl-4fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
automakesource(unstable)1:1.4-p6-13.1medium
automake1.10source(unstable)1:1.10.3-3medium
automake1.10sourcesqueeze1:1.10.3-1+squeeze1medium
automake1.11source(unstable)1:1.11.6-1medium681097
automake1.11sourcesqueeze1:1.11.1-1+squeeze1medium
automake1.7source(unstable)1.7.9-10medium
automake1.7sourcesqueeze1.7.9-9.1+squeeze1medium
automake1.9source(unstable)1.9.6+nogfdl-4medium
automake1.9sourcesqueeze1.9.6+nogfdl-3.1+squeeze1medium

Search for package or bug name: Reporting problems