CVE-2009-4029

NONECVSS 0.0
0.0
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • No confirmed exploitation signals yet
CISA-KEV: Not listedEPSS: 0%CVSS: Exploit: NoneExposed: 0

A fix is available — apply it.

The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete.

CVSS v3
EG Score
0.0(none)
EPSS
38.4%
KEV
Not listed

Published

December 20, 2009

Last Modified

April 23, 2026

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

All Vendor Advisories

(1)

Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.

Frequently asked(4)

What is CVE-2009-4029?
CVE-2009-4029 is a none vulnerability published on December 20, 2009. The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that…
When was CVE-2009-4029 disclosed?
CVE-2009-4029 was first published in the National Vulnerability Database on December 20, 2009, with the most recent update on April 23, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2009-4029 actively exploited?
CVE-2009-4029 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 38.4% percentile likelihood of exploitation in the next 30 days — higher percentiles indicate greater predicted risk.
How do I remediate CVE-2009-4029?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2009-4029, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2009-4029

Explore →

Is Your Infrastructure Affected by CVE-2009-4029?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.