PT-2002-2703 · Xiph.Org · Icecast

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-1982

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Icecast version 1.3.12
Description The issue allows remote attackers to determine if a directory exists by using a .. (dot dot) in the GET request to the list directory function, which returns different error messages depending on whether the directory exists or not.
Recommendations For Icecast version 1.3.12, consider restricting access to the list directory function to minimize the risk of exploitation. As a temporary workaround, avoid using the .. (dot dot) notation in GET requests until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1982

Produtos afetados

Icecast