Icecast Server HTTP Header Buffer Overflow Vulnerability
BID:11271
Info
Icecast Server HTTP Header Buffer Overflow Vulnerability
| Bugtraq ID: | 11271 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2004 12:00AM |
| Updated: | Sep 28 2004 12:00AM |
| Credit: | Luigi Auriemma <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Icecast Icecast 2.0.1 Icecast Icecast 2.0 |
| Not Vulnerable: |
Icecast Icecast 2.0.2 |
Discussion
Icecast Server HTTP Header Buffer Overflow Vulnerability
It is reported that the Icecast server is susceptible to a buffer overflow vulnerability. This issue is due to a failure of the application to properly enforce boundary conditions when dealing with user-supplied input data.
This vulnerability allows for remote code execution in the context of the Icecast server.
It is reported that this vulnerability is only exploitable to execute remote code on Microsoft Windows platforms. This buffer overflow affects all platforms, however it is only exploitable if a sensitive address is located adjacent to the affected buffer. On other platforms, denial of service or code execution may be possible, but this has not been confirmed.
Verions 2.x up to 2.0.1 are reported vulnerable to this issue.
It is reported that the Icecast server is susceptible to a buffer overflow vulnerability. This issue is due to a failure of the application to properly enforce boundary conditions when dealing with user-supplied input data.
This vulnerability allows for remote code execution in the context of the Icecast server.
It is reported that this vulnerability is only exploitable to execute remote code on Microsoft Windows platforms. This buffer overflow affects all platforms, however it is only exploitable if a sensitive address is located adjacent to the affected buffer. On other platforms, denial of service or code execution may be possible, but this has not been confirmed.
Verions 2.x up to 2.0.1 are reported vulnerable to this issue.
Exploit / POC
Icecast Server HTTP Header Buffer Overflow Vulnerability
Exploits have been made available. 'iceexec.zip' was provided by Luigi Auriemma <[email protected]>, and 'iceexec2.zip' was provided by Delikon <[email protected]>:
Exploits have been made available. 'iceexec.zip' was provided by Luigi Auriemma <[email protected]>, and 'iceexec2.zip' was provided by Delikon <[email protected]>:
Solution / Fix
Icecast Server HTTP Header Buffer Overflow Vulnerability
Solution:
The vendor has released version 2.0.2 of Icecast to resolve this issue:
Icecast Icecast 2.0
Icecast Icecast 2.0.1
Solution:
The vendor has released version 2.0.2 of Icecast to resolve this issue:
Icecast Icecast 2.0
-
Icecast icecast-2.0.2.tar.gz
http://svn.xiph.org/releases/icecast/icecast-2.0.2.tar.gz
Icecast Icecast 2.0.1
-
Icecast icecast-2.0.2.tar.gz
http://svn.xiph.org/releases/icecast/icecast-2.0.2.tar.gz
References
Icecast Server HTTP Header Buffer Overflow Vulnerability
References:
References:
- Icecast Homepage (Icecast)
- Code execution in Icecast 2.0.1 (Luigi Auriemma
) - Re:2. Code execution in Icecast 2.0.1(exploit with shellcode) ([email protected])