Unrated severityNVD Advisory· Published Dec 20, 2009· Updated Apr 23, 2026
CVE-2009-4029
CVE-2009-4029
Description
The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- lists.gnu.org/archive/html/automake/2009-12/msg00012.htmlnvdPatch
- lists.gnu.org/archive/html/automake-patches/2009-11/msg00017.htmlnvdExploit
- lists.gnu.org/archive/html/automake/2009-12/msg00010.htmlnvd
- lists.gnu.org/archive/html/automake/2009-12/msg00011.htmlnvd
- lists.gnu.org/archive/html/automake/2009-12/msg00013.htmlnvd
- sunsolve.sun.com/search/document.donvd
- wiki.rpath.com/wiki/Advisories:rPSA-2010-0071nvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/archive/1/514526/100/0/threadednvd
- www.vupen.com/english/advisories/2009/3579nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11717nvd
News mentions
0No linked articles in our index yet.