Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
https://lists.gnu.org/archive/html/automake/2012-07/msg00023.html http://www.vuxml.org/freebsd/36235c38-e0a8-11e1-9f4d-002354ed89bc.html
Insight
The following package is affected: automake
CVE-2012-3386
The 'make distcheck' rule in GNU Automake before 1.11.6 and 1.12.x before 1.12.2 grants world-writable permissions to the extraction directory, which introduces a race condition that allows local users to execute arbitrary code via unspecified vectors.
Severity
Classification
-
CVE CVE-2012-3386 -
CVSS Base Score: 4.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities