First published: Mon Jul 30 2007(Updated: )
The default configuration of Centre for Speech Technology Research (CSTR) Festival 1.95 beta (aka 2.0 beta) on Gentoo Linux, SUSE Linux, and possibly other distributions, is run locally with elevated privileges without requiring authentication, which allows local and remote attackers to execute arbitrary commands via the local daemon on port 1314, a different vulnerability than CVE-2001-0956. NOTE: this issue is local in some environments, but remote on others.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Centre For Speech Technology Research Gentoo Linux | =festival_1.95_beta | |
SUSE Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4074 is considered to have a medium severity due to the potential for local and remote attackers to execute arbitrary code.
To fix CVE-2007-4074, update the CSTR Festival package to a version that is not affected by the vulnerability.
CVE-2007-4074 affects the default configuration of CSTR Festival 1.95 beta on Gentoo Linux, SUSE Linux, and possibly other distributions.
Yes, CVE-2007-4074 can be exploited remotely if the vulnerable configuration is accessible.
The impact of CVE-2007-4074 includes unauthorized execution of arbitrary code, potentially compromising the system's integrity.