vendor:
Icecast
by:
SecurityFocus
7.5
CVSS
HIGH
Buffer Overflow and Information Disclosure
119, 200
CWE
Product Name: Icecast
Affected Version From: 2.2
Affected Version To: 2.2
Patch Exists: YES
Related CWE: N/A
CPE: Icecast
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2005
Icecast Multiple Vulnerabilities
Icecast is reported to be prone to a buffer overflow vulnerability due to a lack of sufficient boundary checks performed on certain XSL tag values before copying these values into a finite buffer in process memory. It is also reported to be prone to an information disclosure vulnerability due to the parser failing to parse XSL files when a request for such a file is appended with a dot '.' character.
Mitigation:
Ensure that all XSL files are parsed securely and that requests for XSL files are not appended with a dot '.' character.