|
Note: This is an archival copy of Security Sun Alert 275650 as previously published on http://sunsolve.sun.com. Latest version of this security advisory is available from http://support.oracle.com as Sun Alert 1021784.1. |
Category Security Release Phase Resolved 6906268 Product OpenSolaris Date of Resolved Release 22-Jan-2010 GNU "Automake" contains a race condition security vulnerability: 1. Impact GNU Automake is a tool for automatically generating "Makefile.in" files compliant with the GNU Coding Standards. GNU Automake contains a race condition security vulnerability that may allow a local unprivileged user to make unauthorized changes to package files or execute arbitrary code with the privileges of another local user when that user is running the "dist" and "distcheck" targets. This issue is also described in the following document:
This issue can occur in the following releases: SPARC Platform
Note 2: This vulnerability only affects OpenSolaris systems that have installed the Automake package (beginning with SUNWgnu-automake). The SUNWgnu-automake package is not installed by default. To determine if the SUNWgnu-automake package is installed, the following command can be run: $ pkg list 'SUNWgnu-automake*'Note 3: OpenSolaris distributions may include additional bug fixes above and beyond the build from which it was derived. To determine the base build of OpenSolaris, the following command can be used: $ uname -v
3. SymptomsThere are no predictable symptoms that would indicate the described issue has been exploited. 4. Workaround To work around the described issue, download and build a newer version of automake (1.10.3, 1.11.1 or later). For example 1.10.3 can be obtained from: ftp://ftp.gnu.org/gnu/automake/automake-1.10.3.tar.gz5. Resolution This issue is resolved in the following releases: SPARC Platform
For more information on Security Sun Alerts, see 1009886.1. Copyright 2000-2010 Sun Microsystems, Inc., 4150 Network Circle, Santa Clara, CA 95054 U.S.A. All rights reserved. Attachments This solution has no attachment | |||||||||||||||
|
|