PT-2007-5277 · Cstr · Cstr Festival

Published

2007-07-30

·

Updated

2018-10-15

·

CVE-2007-4074

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: CSTR Festival version 1.95 beta (aka 2.0 beta)
Description: The default configuration of CSTR Festival allows local and remote attackers to execute arbitrary commands via the local daemon on port 1314, due to it running with elevated privileges without requiring authentication. This issue can be local in some environments but remote in others.
Recommendations: For version 1.95 beta (aka 2.0 beta), consider disabling the daemon on port 1314 until a proper configuration or patch is available to prevent unauthorized access and command execution. Restrict access to the daemon to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-4074

Affected Products

Cstr Festival