CVE Vulnerabilities

CVE-2010-3996

Published: Nov 05, 2010 | Modified: Jan 14, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW

festival_server in Centre for Speech Technology Research (CSTR) Festival, probably 2.0.95-beta and earlier, places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Affected Software

Name Vendor Start Version End Version
Festival Cstr * 2.0.95 (including)
Festival Cstr 1.4.1 (including) 1.4.1 (including)
Festival Cstr 1.4.2 (including) 1.4.2 (including)
Festival Cstr 1.4.3 (including) 1.4.3 (including)
Festival Cstr 1.95 (including) 1.95 (including)
Festival Cstr 1.96 (including) 1.96 (including)
Festival Ubuntu artful *
Festival Ubuntu dapper *
Festival Ubuntu hardy *
Festival Ubuntu karmic *
Festival Ubuntu lucid *
Festival Ubuntu maverick *
Festival Ubuntu natty *
Festival Ubuntu oneiric *
Festival Ubuntu precise *
Festival Ubuntu quantal *
Festival Ubuntu raring *
Festival Ubuntu saucy *
Festival Ubuntu upstream *
Festival Ubuntu utopic *
Festival Ubuntu vivid *
Festival Ubuntu wily *
Festival Ubuntu yakkety *
Festival Ubuntu zesty *

References