CVE-2009-4029
EPSS 0.72%
描述
The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete.
如何修補 CVE-2009-4029
要修補 CVE-2009-4029,請將受影響套件升級到下列已修補版本。
- Debian/automake—升級至 1:1.4-p6-13.1 或更新版本
CVE-2009-4029 正在被利用嗎?
低 — EPSS 為 0.7%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1:1.4-p6-13.1