LWN.net Logo

festival: code execution

Package(s):festival CVE #(s):CVE-2010-3996
Created:October 22, 2010 Updated:November 3, 2010
Description: From the openSUSE advisory:

festival_server uses an unsafe LD_LIBRARY_PATH. Local users could exploit that to execute code as another user if that user runs festival_server.

Alerts:
SUSE SUSE-SR:2010:020 2010-11-03
openSUSE openSUSE-SU-2010:0756-1 2010-10-22
SUSE SUSE-SR:2010:019 2010-10-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds