7.5 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): Present (P)
- Privileges Required (PR): High (H)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): High (H)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): Present (P)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): High (H)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
FreePBX: Authenticated TTS AGI Command Injection Through TTS Name
FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS destination name that is HTML-encoded for storage, decoded during dialplan generation, passed as an AGI argument, and used to build filenames inside agi-bin/propolys-tts.agi. The TTS destination name reaches a raw shell-command execution path, allowing arbitrary operating-system command execution as the asterisk service user. This issue is fixed in versions 16.0.6 and 17.0.5.4.
References
Affected products
- ==>= 17.0.1, < 17.0.5.4
- ==< 16.0.6
Matching in nixpkgs
pkgs.tts
None
pkgs.svox
Text to speech voice sinthesizer from SVox
-
nixos-unstable 0-unstable-2021-05-06
- nixpkgs-unstable 0-unstable-2021-05-06
- nixos-unstable-small 0-unstable-2021-05-06
-
nixos-26.05 0-unstable-2021-05-06
- nixos-26.05-small 0-unstable-2021-05-06
- nixpkgs-26.05-darwin 0-unstable-2021-05-06
pkgs.freetts
Text to speech system based on Festival written in Java
pkgs.marytts
Open-source, multilingual text-to-speech synthesis system written in pure Java
-
nixos-unstable 5.2.1-unstable-2024-10-09
- nixpkgs-unstable 5.2.1-unstable-2024-10-09
- nixos-unstable-small 5.2.1-unstable-2024-10-09
-
nixos-26.05 5.2.1-unstable-2024-10-09
- nixos-26.05-small 5.2.1-unstable-2024-10-09
- nixpkgs-26.05-darwin 5.2.1-unstable-2024-10-09
pkgs.nanotts
Speech synthesizer commandline utility that improves pico2wave, included with SVOX PicoTTS
-
nixos-unstable 2021-02-22
- nixpkgs-unstable 2021-02-22
- nixos-unstable-small 2021-02-22
-
nixos-26.05 2021-02-22
- nixos-26.05-small 2021-02-22
- nixpkgs-26.05-darwin 2021-02-22
pkgs.picotts
Text to speech voice sinthesizer from SVox
-
nixos-unstable 0-unstable-2021-05-06
- nixpkgs-unstable 0-unstable-2021-05-06
- nixos-unstable-small 0-unstable-2021-05-06
-
nixos-26.05 0-unstable-2021-05-06
- nixos-26.05-small 0-unstable-2021-05-06
- nixpkgs-26.05-darwin 0-unstable-2021-05-06
pkgs.piper-tts
Fast, local neural text to speech system
pkgs.pocket-tts
Lightweight text-to-speech (TTS) application designed to run efficiently on CPUs
pkgs.libgringotts
Small library to encapsulate data in an encrypted structure
pkgs.pkgsRocm.tts
None
pkgs.tts-mod-vault
Download and backup assets for your Tabletop Simulator mods
pkgs.pkgsRocm.piper-tts
Fast, local neural text to speech system
pkgs.pkgsRocm.pocket-tts
Lightweight text-to-speech (TTS) application designed to run efficiently on CPUs
pkgs.python313Packages.gtts
Python library and CLI tool to interface with Google Translate text-to-speech API
pkgs.python314Packages.gtts
Python library and CLI tool to interface with Google Translate text-to-speech API
pkgs.python313Packages.pyttsx3
Offline text-to-speech synthesis library
pkgs.python313Packages.trainer
General purpose model trainer, as flexible as it gets
pkgs.python314Packages.pyttsx3
Offline text-to-speech synthesis library
pkgs.python314Packages.trainer
General purpose model trainer, as flexible as it gets
pkgs.python313Packages.edge-tts
Microsoft Edge text-to-speech service WITHOUT Edge, Windows and API keys
pkgs.python314Packages.edge-tts
Microsoft Edge text-to-speech service WITHOUT Edge, Windows and API keys
pkgs.python313Packages.gtts-token
Calculates a token to run the Google Translate text to speech
pkgs.python313Packages.pocket-tts
Lightweight text-to-speech (TTS) application designed to run efficiently on CPUs
pkgs.python314Packages.gtts-token
Calculates a token to run the Google Translate text to speech
pkgs.python314Packages.pocket-tts
Lightweight text-to-speech (TTS) application designed to run efficiently on CPUs
pkgs.python313Packages.ttstokenizer
Tokenizer for Text to Speech (TTS) models
pkgs.python314Packages.ttstokenizer
Tokenizer for Text to Speech (TTS) models
pkgs.python313Packages.growattserver
Python package to retrieve information from Growatt units
pkgs.python313Packages.pycsspeechtts
Python library for Microsoft Cognitive Services Text-to-Speech
pkgs.python314Packages.growattserver
Python package to retrieve information from Growatt units
pkgs.python314Packages.pycsspeechtts
Python library for Microsoft Cognitive Services Text-to-Speech
pkgs.pkgsRocm.python3Packages.trainer
General purpose model trainer, as flexible as it gets
pkgs.pkgsRocm.python3Packages.pocket-tts
Lightweight text-to-speech (TTS) application designed to run efficiently on CPUs
pkgs.python313Packages.brottsplatskartan
Python API wrapper for brottsplatskartan.se
Package maintainers
-
@pSub Pascal Wittmann <mail@pascal-wittmann.de>
-
@pluiedev Leah Amelia Chen <hi@pluie.me>
-
@strikerlulu StrikerLulu <strikerlulu7@gmail.com>
-
@canndrew Andrew Cann <shum@canndrew.org>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@GaetanLepage Gaetan Lepage <gaetan@glepage.com>
-
@Mic92 Jörg Thalheim <joerg@thalheim.io>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@yzhou216 Yiyu Zhou <yiyu@yiyuzhou.io>
-
@unode Renato Alves <alves.rjc@gmail.com>
-
@makefu Felix Richter <makefu@syntax-fehler.de>
-
@JamieMagee Jamie Magee <jamie.magee@gmail.com>
-
@ethindp Ethin Probst <harlydavidsen@gmail.com>
-
@happysalada Raphael Megzari <raphael@megzari.com>
-
@Eschguy Austin Eschweiler <austin.eschweiler@gmail.com>