VYPR

Festival

by Cstr

CVEs (1)

  • CVE-2010-3996Nov 5, 2010
    risk 0.00cvss epss 0.00

    festival_server in Centre for Speech Technology Research (CSTR) Festival, probably 2.0.95-beta and earlier, places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.