Nullsoft SHOUTcast icy-name/icy-url Memory Corruption Vulnerability
BID:8954
Info
Nullsoft SHOUTcast icy-name/icy-url Memory Corruption Vulnerability
| Bugtraq ID: | 8954 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2003 12:00AM |
| Updated: | Nov 03 2003 12:00AM |
| Credit: | Discovery of this issue is credited to HEX <hex@hex_net_ru.securityfocus.com>. |
| Vulnerable: |
NullSoft Shoutcast Server 1.9.2 Win32 |
| Not Vulnerable: | |
Discussion
Nullsoft SHOUTcast icy-name/icy-url Memory Corruption Vulnerability
Nullsoft SHOUTcast Server is prone to a memory corruption vulnerability that may lead to denial of service attacks or code execution. This is due to insufficient bounds checking of server commands supplied by authenticated users, specifically icy-name and icy-url.
This issue was reported in SHOUTcast 1.9.2 on Windows platforms. Other versions and platforms may also be affected.
Nullsoft SHOUTcast Server is prone to a memory corruption vulnerability that may lead to denial of service attacks or code execution. This is due to insufficient bounds checking of server commands supplied by authenticated users, specifically icy-name and icy-url.
This issue was reported in SHOUTcast 1.9.2 on Windows platforms. Other versions and platforms may also be affected.
Exploit / POC
Solution / Fix
Nullsoft SHOUTcast icy-name/icy-url Memory Corruption Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Nullsoft SHOUTcast icy-name/icy-url Memory Corruption Vulnerability
References:
References:
- Shoutcast Homepage (Nullsoft)
- ShoutCast server 1.9.2/win32 (HEX
)