Comment 15 for bug 1023960

Revision history for this message
In , Martin (martin-redhat-bugs) wrote :

IssueDescription:

It was found that the distcheck rule in Automake-generated Makefiles made a directory world-writable when preparing source archives. If a malicious, local user could access this directory, they could execute arbitrary code with the privileges of the user running "make distcheck".