CVE-2012-3386

medium
Published 2012-08-07 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
4.4

Description

The "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1:1.11.6-1
debian debianbullseyefixed1:1.11.6-1
debian debianforkyfixed1:1.4-p6-13.1
debian debiansidfixed1:1.4-p6-13.1

Application impact

VendorProductVersionsFixed
gnuautomake{"endIncluding":"1.11.5"}
gnuautomake1.0
gnuautomake1.2
gnuautomake1.3
gnuautomake1.4
gnuautomake1.5
gnuautomake1.6
gnuautomake1.6.1
gnuautomake1.6.2
gnuautomake1.6.3
gnuautomake1.7
gnuautomake1.7.1
gnuautomake1.7.2
gnuautomake1.7.3
gnuautomake1.7.4
gnuautomake1.7.5
gnuautomake1.7.6
gnuautomake1.7.7
gnuautomake1.7.8
gnuautomake1.7.9
gnuautomake1.8
gnuautomake1.8.1
gnuautomake1.8.2
gnuautomake1.8.3
gnuautomake1.8.4
gnuautomake1.8.5
gnuautomake1.9
gnuautomake1.9.1
gnuautomake1.9.2
gnuautomake1.9.3
gnuautomake1.9.4
gnuautomake1.9.5
gnuautomake1.9.6
gnuautomake1.10
gnuautomake1.10.0.3
gnuautomake1.10.1
gnuautomake1.10.2
gnuautomake1.10.3
gnuautomake1.11.1
gnuautomake1.11.2
gnuautomake1.11.3
gnuautomake1.11.4
gnuautomake1.12
gnuautomake1.12.1

References

CWEs

CWE-264 CWE-362

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.