PDA

View Full Version : Festival Command Execution Vulnerability



newsbot
08-04-2008, 07:45 PM
Festival (http://www.cstr.ed.ac.uk/projects/festival/) offers "a general framework for building speech synthesis systems as well as including examples of various modules". The Festival server is vulnerable to unauthenticated remote code execution.

http://www.securiteam.com/unixfocus/5HP042AO0W.html