Icecast Server Status Display Cross-Site Scripting Vulnerability
BID:11021
Info
Icecast Server Status Display Cross-Site Scripting Vulnerability
| Bugtraq ID: | 11021 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0781 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 24 2004 12:00AM |
| Updated: | Jul 12 2009 06:17AM |
| Credit: | Discovery of this issue is credited to Markus Wörle. |
| Vulnerable: |
Icecast Icecast 1.3.12 Icecast Icecast 1.3.11 Icecast Icecast 1.3.10 -1 Icecast Icecast 1.3.9 -2 Icecast Icecast 1.3.9 -1 Icecast Icecast 1.3.9 Icecast Icecast 1.3.8 Icecast Icecast 1.3.7 -1 Icecast Icecast 1.3.7 Icecast Icecast 1.3.5 -1 Icecast Icecast 1.3.5 Icecast Icecast 1.3 .10 Icecast Icecast 1.3 .0 |
| Not Vulnerable: | |
Discussion
Icecast Server Status Display Cross-Site Scripting Vulnerability
Reportedly Icecast Server is affected by a cross-site scripting vulnerability in the status display functionality. This issue is due to a failure of the application to properly sanitize user-supplied input.
As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of an unsuspecting user when followed. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Reportedly Icecast Server is affected by a cross-site scripting vulnerability in the status display functionality. This issue is due to a failure of the application to properly sanitize user-supplied input.
As a result of this vulnerability, it is possible for a remote attacker to create a malicious link containing script code that will be executed in the browser of an unsuspecting user when followed. This may facilitate the theft of cookie-based authentication credentials as well as other attacks.
Exploit / POC
Icecast Server Status Display Cross-Site Scripting Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Icecast Server Status Display Cross-Site Scripting Vulnerability
Solution:
Debian has released advisory DSA 541-1 dealing with this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Icecast Icecast 1.3.11
Solution:
Debian has released advisory DSA 541-1 dealing with this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Icecast Icecast 1.3.11
-
Debian icecast-server_1.3.11-4.2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/i/icecast-server/icecast- server_1.3.11-4.2_alpha.deb -
Debian icecast-server_1.3.11-4.2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/i/icecast-server/icecast- server_1.3.11-4.2_arm.deb -
Debian icecast-server_1.3.11-4.2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/i/icecast-server/icecast- server_1.3.11-4.2_hppa.deb -
Debian icecast-server_1.3.11-4.2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/i/icecast-server/icecast- server_1.3.11-4.2_i386.deb -
Debian icecast-server_1.3.11-4.2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/i/icecast-server/icecast- server_1.3.11-4.2_ia64.deb -
Debian icecast-server_1.3.11-4.2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/i/icecast-server/icecast- server_1.3.11-4.2_m68k.deb -
Debian icecast-server_1.3.11-4.2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/i/icecast-server/icecast- server_1.3.11-4.2_mips.deb -
Debian icecast-server_1.3.11-4.2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/i/icecast-server/icecast- server_1.3.11-4.2_mipsel.deb -
Debian icecast-server_1.3.11-4.2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/i/icecast-server/icecast- server_1.3.11-4.2_powerpc.deb -
Debian icecast-server_1.3.11-4.2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/i/icecast-server/icecast- server_1.3.11-4.2_s390.deb -
Debian icecast-server_1.3.11-4.2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/i/icecast-server/icecast- server_1.3.11-4.2_sparc.deb
References
Icecast Server Status Display Cross-Site Scripting Vulnerability
References:
References:
- Icecast Homepage (Icecast)