PT-2002-2703 · Xiph.Org · Icecast
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-1982
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Icecast version 1.3.12
Description
The issue allows remote attackers to determine if a directory exists by using a .. (dot dot) in the GET request to the list directory function, which returns different error messages depending on whether the directory exists or not.
Recommendations
For Icecast version 1.3.12, consider restricting access to the list directory function to minimize the risk of exploitation. As a temporary workaround, avoid using the .. (dot dot) notation in GET requests until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Icecast