VYPR
Unrated severityNVD Advisory· Published Dec 20, 2009· Updated Apr 23, 2026

CVE-2009-4029

CVE-2009-4029

Description

The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete.

Affected products

3
  • GNU/Automake3 versions
    cpe:2.3:a:gnu:automake:1.10.3:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:gnu:automake:1.10.3:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:automake:1.11.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:automake:branch:1-9:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

11

News mentions

0

No linked articles in our index yet.