This script is Copyright (C) 2007-2015 Tenable Network Security, Inc.
The remote Gentoo host is missing one or more security-related
The remote host is affected by the vulnerability described in GLSA-200707-10
(Festival: Privilege elevation)
Konstantine Shirow reported a vulnerability in default Gentoo
configurations of Festival. The daemon is configured to run with root
privileges and to listen on localhost, without requiring a password.
A local attacker could gain root privileges by connecting to the daemon
and execute arbitrary commands.
Set a password in the configuration file /etc/festival/server.scm by
adding the line: (set! server_passwd password)
See also :
All Festival users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose '>=app-accessibility/festival-1.95_beta-r4'
Risk factor :
Family: Gentoo Local Security Checks
Nessus Plugin ID: 25792 (gentoo_GLSA-200707-10.nasl)
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.