CVE Vulnerabilities

CVE-2007-4074

Published: Jul 30, 2007 | Modified: Oct 15, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
LOW

The default configuration of Centre for Speech Technology Research (CSTR) Festival 1.95 beta (aka 2.0 beta) on Gentoo Linux, SUSE Linux, and possibly other distributions, is run locally with elevated privileges without requiring authentication, which allows local and remote attackers to execute arbitrary commands via the local daemon on port 1314, a different vulnerability than CVE-2001-0956. NOTE: this issue is local in some environments, but remote on others.

Affected Software

Name Vendor Start Version End Version
Gentoo_linux Centre_for_speech_technology_research festival_1.95_beta (including) festival_1.95_beta (including)
Suse_linux Suse * *
Festival Ubuntu dapper *
Festival Ubuntu devel *
Festival Ubuntu edgy *
Festival Ubuntu feisty *
Festival Ubuntu gutsy *
Festival Ubuntu hardy *
Festival Ubuntu intrepid *
Festival Ubuntu jaunty *

References