CVE-2012-3386

UnknownEPSS 0.47%

Last modified

CVE-2012-3386 is a vulnerability of currently unknown severity. The "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.

Description

The "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.

Metrics

CVSS 3.0
/10
EPSS Probability
0.47%

37.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
GnuAutomake<= 1.11.5
GnuAutomake1.0
GnuAutomake1.2
GnuAutomake1.3
GnuAutomake1.4
GnuAutomake1.5
GnuAutomake1.6
GnuAutomake1.6.1
GnuAutomake1.6.2
GnuAutomake1.6.3
GnuAutomake1.7
GnuAutomake1.7.1
GnuAutomake1.7.2
GnuAutomake1.7.3
GnuAutomake1.7.4
GnuAutomake1.7.5
GnuAutomake1.7.6
GnuAutomake1.7.7
GnuAutomake1.7.8
GnuAutomake1.7.9
GnuAutomake1.8
GnuAutomake1.8.1
GnuAutomake1.8.2
GnuAutomake1.8.3
GnuAutomake1.8.4
GnuAutomake1.8.5
GnuAutomake1.9
GnuAutomake1.9.1
GnuAutomake1.9.2
GnuAutomake1.9.3
GnuAutomake1.9.4
GnuAutomake1.9.5
GnuAutomake1.9.6
GnuAutomake1.10
GnuAutomake1.10.0.3
GnuAutomake1.10.1
GnuAutomake1.10.2
GnuAutomake1.10.3
GnuAutomake1.11.1
GnuAutomake1.11.2
GnuAutomake1.11.3
GnuAutomake1.11.4
GnuAutomake1.12
GnuAutomake1.12.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-3386?
The "make distcheck" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.
How severe is CVE-2012-3386?
Severity scoring for CVE-2012-3386 is pending analysis. The EPSS model estimates a 0.47% probability of exploitation in the next 30 days.
How do I fix CVE-2012-3386?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-3386?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST