vendor:
SpeechD
by:
7.5
CVSS
HIGH
Command Execution
CWE
Product Name: SpeechD
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
SpeechD Local Command Execution Vulnerability
SpeechD, a device-independent layer for speech synthesis under Linux, is vulnerable to a local command execution flaw. This vulnerability allows a local user to pass malicious commands to the /dev/speech device, which can be executed with the privilege level of the speechd user (usually root). An attacker can exploit this vulnerability by injecting malicious commands using the echo command and redirecting the output to /dev/speech.
Mitigation:
The vendor has not provided a patch or mitigation for this vulnerability.