10
CVSSv2

CVE-2007-4074

Published: 30/07/2007 Updated: 15/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The default configuration of Centre for Speech Technology Research (CSTR) Festival 1.95 beta (aka 2.0 beta) on Gentoo Linux, SUSE Linux, and possibly other distributions, is run locally with elevated privileges without requiring authentication, which allows local and remote malicious users to execute arbitrary commands via the local daemon on port 1314, a different vulnerability than CVE-2001-0956. NOTE: this issue is local in some environments, but remote on others.

Vulnerable Product Search on Vulmon Subscribe to Product

centre for speech technology research gentoo linux festival_1.95_beta

suse suse linux

Vendor Advisories

Debian Bug report logs - #435445 CVE-2007-4074: priviledge escalation in festival Package: festival; Maintainer for festival is Debian TTS Team <tts-project@listsaliothdebianorg>; Source for festival is src:festival (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Tue, 31 Jul 2007 19:30:01 ...