CVE-2009-4135
published 2009-12-11CVE-2009-4135: The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree…
PriorityP418medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.38%
30.1th percentile
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | coreutils | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
| gnu | coreutils | — | — |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4LOW
vendor_redhat4.4MEDIUM
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
coreutils vulnerabilities
vendor_ubuntu·2015-01-14·CVSS 4.4
CVE-2009-4135 [MEDIUM] coreutils vulnerabilities
Title: coreutils vulnerabilities
Summary: date and touch could be made to crash or run programs if they
handled specially crafted input.
It was discovered that the distcheck rule in dist-check.mk in GNU
coreutils allows local users to gain privileges via a symlink attack
on a directory tree under /tmp. This issue only affected Ubuntu 10.04 LTS.
(CVE-2009-4135)
Bertrand Jacquin and Fiedler Roman discovered date and touch incorrectly
handled user-supplied input. An attacker could possibly use this to cause
a denial of service or potentially execute code. (CVE-2014-9471)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
coreutils: Unsafe temporary directory use in "distcheck" rule
vendor_redhat·2009-12-07·CVSS 4.4
CVE-2009-4135 [MEDIUM] coreutils: Unsafe temporary directory use in "distcheck" rule
coreutils: Unsafe temporary directory use in "distcheck" rule
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
Statement: This issue does not affect users using coreutils binary RPMs, or rebuilding source RPMs. Therefore, we do not plan to release updates addressing this flaw on Red Hat Enterprise Linux 3, 4 and 5.
For additional details, refer to the following bug: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-4135
Debian
CVE-2009-4135: coreutils - The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows lo...
vendor_debian·2009·CVSS 4.4
CVE-2009-4135 [MEDIUM] CVE-2009-4135: coreutils - The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows lo...
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-q7ww-m6jm-qmwq: The distcheck rule in dist-check
ghsa_unreviewed·2022-05-02
CVE-2009-4135 [MEDIUM] CWE-59 GHSA-q7ww-m6jm-qmwq: The distcheck rule in dist-check
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
OSV
coreutils vulnerabilities
osv·2015-01-14·CVSS 4.4
CVE-2009-4135 [MEDIUM] coreutils vulnerabilities
coreutils vulnerabilities
It was discovered that the distcheck rule in dist-check.mk in GNU
coreutils allows local users to gain privileges via a symlink attack
on a directory tree under /tmp. This issue only affected Ubuntu 10.04 LTS.
(CVE-2009-4135)
Bertrand Jacquin and Fiedler Roman discovered date and touch incorrectly
handled user-supplied input. An attacker could possibly use this to cause
a denial of service or potentially execute code. (CVE-2014-9471)
No detection rules found.
No public exploits indexed.
http://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=ae034822c535fa5http://marc.info/?l=oss-security&m=126030454503441&w=2http://secunia.com/advisories/37645http://secunia.com/advisories/37860http://secunia.com/advisories/62226http://www.mail-archive.com/bug-coreutils%40gnu.org/msg18779.htmlhttp://www.mail-archive.com/bug-coreutils%40gnu.org/msg18787.htmlhttp://www.openwall.com/lists/oss-security/2009/12/08/4http://www.osvdb.org/60853http://www.securityfocus.com/bid/37256http://www.ubuntu.com/usn/USN-2473-1http://www.vupen.com/english/advisories/2009/3453https://bugzilla.redhat.com/show_bug.cgi?id=545439https://exchange.xforce.ibmcloud.com/vulnerabilities/54673https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00954.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00972.htmlhttp://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=ae034822c535fa5http://marc.info/?l=oss-security&m=126030454503441&w=2http://secunia.com/advisories/37645http://secunia.com/advisories/37860http://secunia.com/advisories/62226http://www.mail-archive.com/bug-coreutils%40gnu.org/msg18779.htmlhttp://www.mail-archive.com/bug-coreutils%40gnu.org/msg18787.htmlhttp://www.openwall.com/lists/oss-security/2009/12/08/4http://www.osvdb.org/60853http://www.securityfocus.com/bid/37256http://www.ubuntu.com/usn/USN-2473-1http://www.vupen.com/english/advisories/2009/3453https://bugzilla.redhat.com/show_bug.cgi?id=545439https://exchange.xforce.ibmcloud.com/vulnerabilities/54673https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00954.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00972.html
2009-12-11
Published