Release date:
Updated on:
Affected Systems:
GNU Automake 1.8.3
GNU Automake 1.8.2
GNU Automake 1.8.1
GNU Automake 1.7.9
GNU Automake 1.7.8
GNU Automake 1.7.7
GNU Automake 1.7.6
GNU Automake 1.7.5
GNU Automake 1.7.4
GNU Automake 1.7.3
GNU Automake 1.7.2
GNU Automake 1.7.1
GNU Automake 1.7
GNU Automake 1.11.1
GNU Automake 1.11
GNU Automake 1.10.3
GNU Automake 1.10.2
MandrakeSoft Enterprise Server 5 x86_64
MandrakeSoft Enterprise Server 5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54418
Cve id: CVE-2012-3386
GNU Automake is a tool that automatically generates 'makefile. in' files that comply with the GNU coding standards.
In versions earlier than GNU Automake 1.12.1, a local code execution vulnerability exists. Attackers can exploit this vulnerability to execute arbitrary code with the current user permission.
<* Source: Stefano Lattarini
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
GNU
---
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.gnu.org