CVE-2010-3996
05.11.2010, 17:00
festival_server in Centre for Speech Technology Research (CSTR) Festival, probably 2.0.95-beta and earlier, places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.Enginsight
Vendor | Product | Version |
---|---|---|
cstr | festival | 𝑥 ≤ 2.0.95 |
cstr | festival | 1.4.1 |
cstr | festival | 1.4.2 |
cstr | festival | 1.4.3 |
cstr | festival | 1.95 |
cstr | festival | 1.96 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
festival |
|
References