A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted header, leading to denial of service and potentially remote code execution.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade icecast | Aug 22, 2024 | Nov 5, 2018 |
| Debian | — | Upgrade icecast2 | Feb 19, 2019 | Nov 5, 2018 |
| Gentoo Linux | — | Upgrade net-misc/icecast. | Nov 12, 2018 | Nov 5, 2018 |
| Suse | — | Upgrade icecast-docUpgrade icecast | Nov 16, 2018 | Nov 4, 2018 |
| Ubuntu | — | Upgrade icecast2 | Nov 19, 2024 | Nov 5, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub