CVE-2007-4529

Publication date 25 August 2007

Last updated 17 July 2025


Ubuntu priority

Description

The WebAdmin interface in TeamSpeak Server 2.0.20.1 allows remote authenticated users with the ServerAdmin flag to assign Registered users certain privileges, resulting in a privilege set that extends beyond that ServerAdmin's own servers, as demonstrated by the (1) AdminAddServer, (2) AdminDeleteServer, (3) AdminStartServer, and (4) AdminStopServer privileges; and administration of arbitrary virtual servers via a request to a .tscmd URI with a modified serverid parameter, as demonstrated by (a) add_server.tscmd, (b) ask_delete_server.tscmd, (c) start_server.tscmd, and (d) stop_server.tscmd.

Status

Package Ubuntu Release Status
teamspeak-server 7.10 gutsy
Fixed 2.0.23.19-1
7.04 feisty Not in release
6.10 edgy Not in release
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities