PT-2007-5277 · Cstr · Cstr Festival

Publicado

2007-07-30

·

Atualizado

2018-10-15

·

CVE-2007-4074

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: CSTR Festival version 1.95 beta (aka 2.0 beta)
Description: The default configuration of CSTR Festival allows local and remote attackers to execute arbitrary commands via the local daemon on port 1314, due to it running with elevated privileges without requiring authentication. This issue can be local in some environments but remote in others.
Recommendations: For version 1.95 beta (aka 2.0 beta), consider disabling the daemon on port 1314 until a proper configuration or patch is available to prevent unauthorized access and command execution. Restrict access to the daemon to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-4074

Produtos afetados

Cstr Festival