PT-2007-5277 · Cstr · Cstr Festival
Published
2007-07-30
·
Updated
2018-10-15
·
CVE-2007-4074
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
CSTR Festival version 1.95 beta (aka 2.0 beta)
Description:
The default configuration of CSTR Festival allows local and remote attackers to execute arbitrary commands via the local daemon on port 1314, due to it running with elevated privileges without requiring authentication. This issue can be local in some environments but remote in others.
Recommendations:
For version 1.95 beta (aka 2.0 beta), consider disabling the daemon on port 1314 until a proper configuration or patch is available to prevent unauthorized access and command execution. Restrict access to the daemon to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cstr Festival