Festival Insecure Command Local Privilege Escalation and Remote Code Execution Vulnerability
BID:25069
Info
Festival Insecure Command Local Privilege Escalation and Remote Code Execution Vulnerability
| Bugtraq ID: | 25069 |
| Class: | Design Error |
| CVE: |
CVE-2007-4074 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 25 2007 12:00AM |
| Updated: | Apr 04 2008 11:08PM |
| Credit: | Konstantine Shirow is credited with the discovery of this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 The Center for Speech Techology Research (CSTR) Festival 1.95 (2.0 beta) SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SuSE Linux 10.1 SuSE Linux 10.0 S.u.S.E. openSUSE 10.3 Gentoo app-accessibility/festival 1.95 Beta-R3 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
Gentoo app-accessibility/festival 1.95_beta-r4 |
Discussion
Festival Insecure Command Local Privilege Escalation and Remote Code Execution Vulnerability
Festival is prone to a privilege-escalation and code-execution vulnerability.
Local attackers can exploit this issue to gain superuser privileges on computers running the affected application.
Under certain circumstances, this issue may allow remote code to run. This depends on the configuration of the affected daemon process.
This issue affects Festival 1.95 (2.0 beta) and prior versions.
Festival is prone to a privilege-escalation and code-execution vulnerability.
Local attackers can exploit this issue to gain superuser privileges on computers running the affected application.
Under certain circumstances, this issue may allow remote code to run. This depends on the configuration of the affected daemon process.
This issue affects Festival 1.95 (2.0 beta) and prior versions.
Exploit / POC
Festival Insecure Command Local Privilege Escalation and Remote Code Execution Vulnerability
To exploit this vulnerability, a local attacker issues arbitrary commands to 127.0.0.1:1314.
To exploit this vulnerability, a local attacker issues arbitrary commands to 127.0.0.1:1314.
Solution / Fix
Festival Insecure Command Local Privilege Escalation and Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Festival Insecure Command Local Privilege Escalation and Remote Code Execution Vulnerability
References:
References:
- Analysis of Debian's CVE-2007-4074 response (Tim Brown)
- app-accessibility/festival: privilege elevation with current default setup (Gentoo)
- Bug #130348 in festival (Ubuntu) (Ubuntu)
- Debian Bug report logs - #466146 (Debian)
- Vendor Homepage (The Center for Speech Technology Research)
- Medium security hole affecting Festival on Debian unstable/testing and Ubuntu Ha (Tim Brown
)