Upstream information
Description
festival_server in Centre for Speech Technology Research (CSTR) Festival, probably 2.0.95-beta and earlier, places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.NVD CVSS v2 Base Score: 6.9 (AV:L/AC:M/Au:N/C:C/I:C/A:C)
Novell/SUSE information
Novell Bugzilla entry: 642507 SUSE Security Advisories:- SUSE-SR:2010:019, published Mon, 25 Oct 2010 13:00:00 +0000
- SUSE-SR:2010:020, published Wed, 03 Nov 2010 12:00:00 +0000
- openSUSE-SU-2010:0756-1, published Fri, 22 Oct 2010 18:08:10 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 11.1 |
| |
| openSUSE 11.1 |
| |
| openSUSE 11.2 |
| |
| openSUSE 11.2 |
| |
| openSUSE 11.3 |
| |
| openSUSE 11.3 |
|
