Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as demonstrated by a request to "admin/killsource?mount=/test.ogg."
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade icecast | Aug 30, 2017 | Apr 29, 2015 |
| Debian | — | Upgrade icecast2 | Jul 30, 2024 | Apr 29, 2015 |
| Gentoo Linux | — | Upgrade net-misc/icecast. | Oct 30, 2017 | Apr 29, 2015 |
| Suse | — | Upgrade icecast-debugsourceUpgrade icecastUpgrade icecast-debuginfoUpgrade icecast-doc | Dec 18, 2015 | Apr 16, 2015 |
| Ubuntu | — | Upgrade icecast2 | Nov 19, 2024 | Apr 29, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub