CVE-2010-3996
Published Nov 5, 2010
Last updated 14 years ago
Overview
- Description
- festival_server in Centre for Speech Technology Research (CSTR) Festival, probably 2.0.95-beta and earlier, places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.9
- Impact score
- 10
- Exploitability score
- 3.4
- Vector string
- AV:L/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cstr:festival:*:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E43511A2-2127-49A4-8D5C-E3491C957481", "versionEndIncluding": "2.0.95" }, { "criteria": "cpe:2.3:a:cstr:festival:1.4.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92591D85-9A92-43B0-8891-E66478FE50D3" }, { "criteria": "cpe:2.3:a:cstr:festival:1.4.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0A58236B-A4A1-479D-A157-D72EF14353F3" }, { "criteria": "cpe:2.3:a:cstr:festival:1.4.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B73C886-7D10-4D52-AA08-9EEAD20FC0B3" }, { "criteria": "cpe:2.3:a:cstr:festival:1.95:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D54195E-57A1-4C31-ACBD-DFE793A43FB9" }, { "criteria": "cpe:2.3:a:cstr:festival:1.96:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2394DDC8-B689-423D-AC3E-D1FF8ECD69A4" } ], "operator": "OR" } ] } ]