6.9

CVE-2010-3996

festival_server in Centre for Speech Technology Research (CSTR) Festival, probably 2.0.95-beta and earlier, places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CstrFestival Updatebeta Version <= 2.0.95
CstrFestival Version1.4.1
CstrFestival Version1.4.2
CstrFestival Version1.4.3
CstrFestival Version1.95
CstrFestival Version1.96
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.243
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00001.html
http://lists.opensuse.org/opensuse-updates/2010-10/msg00028.html
http://www.securityfocus.com/bid/44395
https://bugzilla.novell.com/show_bug.cgi?id=642507