Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Full Disclosure: Medium security hole affecting Festival on Debian unstable/testing and Ubuntu Hardy Heron

Medium security hole affecting Festival on Debian unstable/testing and Ubuntu Hardy Heron

From: Tim Brown <timb_at_nth-dimension.org.uk>
Date: Fri, 4 Apr 2008 00:23:56 +0100

It has been recently been identified that the Festival text to speech server
was vulnerable to unauthenticated remote code execution. Further research
indicated that this vulnerability has already been reported as a local
privilege escalation against both the Gentoo and SuSE GNU/Linux distributions
and had assigned CVE-2007-4074. The remote form of this vulnerability was
originally identified in the default configuration of Festival 1.96~beta-5 as
distributed in Debian unstable but Ubuntu Hardy Heron was also affected. Both
Debian and Ubuntu have since released patches to resolve this flaw. An
advisory for this flaw which provides further information is attached. A
short analysis of Debian's response can be found at
http://www.nth-dimension.org.uk/blog.php?id=68.

Cheers,
Tim

-- 
Tim Brown
<mailto:timb_at_nth-dimension.org.uk>
<http://www.nth-dimension.org.uk/>


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Received on Apr 05 2008
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]