PT-2005-1867 · Icecast+1 · Icecast+1

Publicado

2005-03-22

·

Atualizado

2017-07-11

·

CVE-2005-0838

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions IceCast version 2.20
Description The issue is related to multiple buffer overflows in the XSL parser, which may allow attackers to cause a denial of service and possibly execute arbitrary code. This can be achieved through a long test value in an xsl:when tag, a long test value in an xsl:if tag, or a long select value in an xsl:value-of tag.
Recommendations For IceCast version 2.20, consider disabling the XSL parser functionality until a patch is available to prevent potential exploitation. Restrict access to the XSL parser to minimize the risk of denial of service or arbitrary code execution. Avoid using long test values in xsl:when and xsl:if tags, as well as long select values in xsl:value-of tags, in the affected XSL parser.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0838

Produtos afetados

Debian
Icecast