The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete.
CVE-2009-4029
NONECVSS 0.0
0.0
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
- No confirmed exploitation signals yet
CISA-KEV: Not listedEPSS: 0%CVSS: —Exploit: NoneExposed: 0
A fix is available — apply it.
- CVSS v3
- —
- EG Score
- 0.0(none)
- EPSS
- 38.4%
- KEV
- Not listed
Published
December 20, 2009
Last Modified
April 23, 2026
References (24)
- secalert@redhathttp://lists.gnu.org/archive/html/automake-patches/2009-11/msg00017.html
- secalert@redhathttp://lists.gnu.org/archive/html/automake/2009-12/msg00010.html
- secalert@redhathttp://lists.gnu.org/archive/html/automake/2009-12/msg00011.html
- secalert@redhathttp://lists.gnu.org/archive/html/automake/2009-12/msg00012.html
- secalert@redhathttp://lists.gnu.org/archive/html/automake/2009-12/msg00013.html
- secalert@redhathttp://savannah.gnu.org/forum/forum.php?forum_id=6077
- secalert@redhathttp://sunsolve.sun.com/search/document.do?assetkey=1-77-1021784.1-1
- secalert@redhathttp://wiki.rpath.com/wiki/Advisories:rPSA-2010-0071
- secalert@redhathttp://www.mandriva.com/security/advisories?name=MDVSA-2010:203
- secalert@redhathttp://www.securityfocus.com/archive/1/514526/100/0/threaded
- secalert@redhathttp://www.vupen.com/english/advisories/2009/3579
- secalert@redhathttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11717
- af854a3a-2127-422b-91ae-364da2661108http://lists.gnu.org/archive/html/automake-patches/2009-11/msg00017.html
- af854a3a-2127-422b-91ae-364da2661108http://lists.gnu.org/archive/html/automake/2009-12/msg00010.html
- af854a3a-2127-422b-91ae-364da2661108http://lists.gnu.org/archive/html/automake/2009-12/msg00011.html
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
All Vendor Advisories
(1)
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
Frequently asked(4)
What is CVE-2009-4029?
CVE-2009-4029 is a none vulnerability published on December 20, 2009. The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that…
When was CVE-2009-4029 disclosed?
CVE-2009-4029 was first published in the National Vulnerability Database on December 20, 2009, with the most recent update on April 23, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2009-4029 actively exploited?
CVE-2009-4029 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 38.4% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
How do I remediate CVE-2009-4029?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2009-4029, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2009-4029
Is Your Infrastructure Affected by CVE-2009-4029?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.