Icecast Directory Traversal Vulnerability

BID:2932

Info

Icecast Directory Traversal Vulnerability

Bugtraq ID: 2932
Class: Input Validation Error
CVE:
Remote: Yes
Local: No
Published: Jun 26 2001 12:00AM
Updated: Jun 26 2001 12:00AM
Credit: This vulnerability was submitted to BugTraq on June 26th, 2001 by gollum <[email protected]> from Digit-Labs.
Vulnerable: Icecast Icecast 1.3.9 -2
Icecast Icecast 1.3.9 -1
Icecast Icecast 1.3.9
Icecast Icecast 1.3.8 beta2
Icecast Icecast 1.3.8
Icecast Icecast 1.3.7 -1
Icecast Icecast 1.3.7
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server
Icecast Icecast 1.3.5 -1
Icecast Icecast 1.3.5
Icecast Icecast 1.3 .10
+ Caldera OpenLinux Server 3.1.1
+ Caldera OpenLinux Server 3.1
Icecast Icecast 1.3 .0
Icecast Icecast 1.1.4
Icecast Icecast 1.1.3
Icecast Icecast 1.1.2
Icecast Icecast 1.1.1
Icecast Icecast 1.1 .0
Icecast Icecast 1.0 .0
- Debian Linux 2.2 sparc
- Debian Linux 2.2 powerpc
- Debian Linux 2.2 arm
- Debian Linux 2.2 alpha
- Debian Linux 2.2 68k
- Debian Linux 2.2
Not Vulnerable: Icecast Icecast 1.3.10 -1

Discussion

Icecast Directory Traversal Vulnerability

Icecast is an open source audio-streaming server for both Unix and Microsoft Windows systems.

Icecast does not filter encoded characters from URLs when receiving web requests. If a remote attacker crafts a URL containing the ASCII equivalent of directory traversal characters, it is possible to escape Icecast's "root" directory. This will allow the attacker to view files readable by the ownership and group membership of the icecast server.

Exploit / POC

Icecast Directory Traversal Vulnerability

GoLLuM.no <[email protected]> provided this example:

Mp3-files residing outside the Web catalog can be accessed by replacing ascii-values for each ".", thus using "/%2E%2E/" instead of "/../" will walk one folder downward.

Place a mp3-file named "test1.mp3" in the directory below the one you specified in the variable "staticdir".

Then write the following in your browser:

http://localhost:8000/file/../test1.mp3 - Will fail in getting the file

http://localhost:8000/file/%2E%2E/test1.mp3 - Will succeed in getting the file

Solution / Fix

Icecast Directory Traversal Vulnerability

Solution:
Vendor fixes available:


Icecast Icecast 1.0 .0

Icecast Icecast 1.1 .0

Icecast Icecast 1.1.1

Icecast Icecast 1.1.2

Icecast Icecast 1.1.3

Icecast Icecast 1.1.4

Icecast Icecast 1.3 .0

Icecast Icecast 1.3 .10

Icecast Icecast 1.3.5 -1

Icecast Icecast 1.3.5

Icecast Icecast 1.3.7 -1

Icecast Icecast 1.3.7

Icecast Icecast 1.3.8 beta2

Icecast Icecast 1.3.8

Icecast Icecast 1.3.9 -1

Icecast Icecast 1.3.9

Icecast Icecast 1.3.9 -2

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report