"make distcheck" is exploitable: get a fixed automake

Richard W.M. Jones rjones at redhat.com
Fri Jul 13 20:30:21 UTC 2012


On Fri, Jul 13, 2012 at 03:34:53PM +0200, Jim Meyering wrote:
> It's fixed in the latest, automake-12.2

I think you mean 1.12.2 :-)

>     http://bugzilla.redhat.com/CVE-2012-3386
>     http://savannah.gnu.org/forum/forum.php?forum_id=7294

However I don't think I see any fixed Fedora builds (1.12.2 or 1.11.6)
yet.

Rich.

-- 
Richard Jones, Virtualization Group, Red Hat http://people.redhat.com/~rjones
Read my programming blog: http://rwmj.wordpress.com
Fedora now supports 80 OCaml packages (the OPEN alternative to F#)
http://cocan.org/getting_started_with_ocaml_on_red_hat_and_fedora


More information about the devel mailing list