CVE Vulnerabilities

CVE-2010-3996

Published: Nov 05, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
3.7 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

festival_server in Centre for Speech Technology Research (CSTR) Festival, probably 2.0.95-beta and earlier, places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

Affected Software

NameVendorStart VersionEnd Version
FestivalCstr*2.0.95 (including)
FestivalCstr1.4.1 (including)1.4.1 (including)
FestivalCstr1.4.2 (including)1.4.2 (including)
FestivalCstr1.4.3 (including)1.4.3 (including)
FestivalCstr1.95 (including)1.95 (including)
FestivalCstr1.96 (including)1.96 (including)
FestivalUbuntuartful*
FestivalUbuntudapper*
FestivalUbuntuhardy*
FestivalUbuntukarmic*
FestivalUbuntulucid*
FestivalUbuntumaverick*
FestivalUbuntunatty*
FestivalUbuntuoneiric*
FestivalUbuntuprecise*
FestivalUbuntuquantal*
FestivalUbunturaring*
FestivalUbuntusaucy*
FestivalUbuntuupstream*
FestivalUbuntuutopic*
FestivalUbuntuvivid*
FestivalUbuntuwily*
FestivalUbuntuyakkety*
FestivalUbuntuzesty*

References