{"id":"DEBIAN-CVE-2012-3386","details":"The \"make distcheck\" rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.","modified":"2026-09-05T06:47:39.824353900Z","published":"2012-08-07T21:55:01.420Z","upstream":["CVE-2012-3386"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2012-3386"}],"affected":[{"package":{"name":"automake","ecosystem":"Debian:14","purl":"pkg:deb/debian/automake?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.4-p6-13.1"}]}],"versions":["1.0-0","1.0-1","1.0-4","1.3-1","1.3-2","1.4-8","1:1.4-p4-1.1","1:1.4-p6-10","1:1.4-p6-11","1:1.4-p6-12","1:1.4-p6-13","1:1.4-p6-9"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2012-3386.json"}},{"package":{"name":"automake1.11","ecosystem":"Debian:12","purl":"pkg:deb/debian/automake1.11?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:1.11.6-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2012-3386.json"}}],"schema_version":"1.9.0"}