Icecast 'error.log' Security Bypass Vulnerability
BID:56176
Info
Icecast 'error.log' Security Bypass Vulnerability
| Bugtraq ID: | 56176 |
| Class: | Design Error |
| CVE: |
CVE-2011-4612 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2011 12:00AM |
| Updated: | May 07 2015 05:11PM |
| Credit: | Moritz Naumann |
| Vulnerable: |
Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Icecast Icecast 2.3.2 |
| Not Vulnerable: |
Icecast Icecast 2.3.3 |
Discussion
Icecast 'error.log' Security Bypass Vulnerability
Icecast is prone to a security-bypass vulnerability.
Successful exploits of this issue allow an attacker to bypass certain security restrictions and perform unauthorized actions which may lead to further attacks.
Versions prior to Icecast 2.3.3 are vulnerable.
Icecast is prone to a security-bypass vulnerability.
Successful exploits of this issue allow an attacker to bypass certain security restrictions and perform unauthorized actions which may lead to further attacks.
Versions prior to Icecast 2.3.3 are vulnerable.
Exploit / POC
Icecast 'error.log' Security Bypass Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Icecast 'error.log' Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Icecast 'error.log' Security Bypass Vulnerability
References:
References:
- Icecast Homepage (Icecast)
- Newline injection in error.log (Moritz Naumann)