PT-2002-2703 · Xiph.Org · Icecast

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-1982

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Icecast version 1.3.12
Description The issue allows remote attackers to determine if a directory exists by using a .. (dot dot) in the GET request to the list directory function, which returns different error messages depending on whether the directory exists or not.
Recommendations For Icecast version 1.3.12, consider restricting access to the list directory function to minimize the risk of exploitation. As a temporary workaround, avoid using the .. (dot dot) notation in GET requests until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1982

Affected Products

Icecast