Icecast AVLLib Buffer Overflow Vulnerability
BID:4415
Info
Icecast AVLLib Buffer Overflow Vulnerability
| Bugtraq ID: | 4415 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0177 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 03 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Vulnerability discovery credited to <[email protected]>. |
| Vulnerable: |
Icecast Icecast WIN32 1.3.7 Icecast Icecast 1.3.11 Icecast Icecast 1.3.10 -1 Icecast Icecast 1.3.9 -2 Icecast Icecast 1.3.9 -1 Icecast Icecast 1.3.9 Icecast Icecast 1.3.8 beta2 Icecast Icecast 1.3.8 Icecast Icecast 1.3.7 -1 Icecast Icecast 1.3.7 Icecast Icecast 1.3.5 -1 Icecast Icecast 1.3.5 Icecast Icecast 1.3 .10 Icecast Icecast 1.3 .0 Icecast Icecast 1.1.4 Icecast Icecast 1.1.3 Icecast Icecast 1.1.2 Icecast Icecast 1.1.1 Icecast Icecast 1.1 .0 Icecast Icecast 1.0 .0 |
| Not Vulnerable: |
Icecast Icecast 1.3.12 |
Discussion
Icecast AVLLib Buffer Overflow Vulnerability
Icecast is a freely available, open source streaming audio server. Icecast is available for the Unix, Linux, and Microsoft Windows platforms.
Icecast does not properly check bounds on data sent from clients. Because of this, it is possible for a remote user to send an arbitrarily long string of data to the server, which could result in a stack overflow, and the execution of user supplied code. The code would be executed with the privileges of the Icecast server.
Icecast is a freely available, open source streaming audio server. Icecast is available for the Unix, Linux, and Microsoft Windows platforms.
Icecast does not properly check bounds on data sent from clients. Because of this, it is possible for a remote user to send an arbitrarily long string of data to the server, which could result in a stack overflow, and the execution of user supplied code. The code would be executed with the privileges of the Icecast server.