|
|
| |
|
| |
festival: code execution
| Package(s): | festival |
CVE #(s): | CVE-2010-3996
|
| Created: | October 22, 2010 |
Updated: | November 3, 2010 |
| Description: |
From the openSUSE advisory:
festival_server uses an unsafe LD_LIBRARY_PATH. Local users
could exploit that to execute code as another user if that
user runs festival_server. |
| Alerts: |
|
( Log in to post comments)
|
|
|