PT-2003-2126 · Nullsoft · Nullsoft Shoutcast Server

Published

2003-12-31

·

Updated

2017-07-11

·

CVE-2003-1174

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions NullSoft Shoutcast Server version 1.9.2
Description The issue allows local users to cause a denial of service. This can be achieved via two methods: (1) by using icy-name followed by a long server name, or (2) by using icy-url followed by a long URL.
Recommendations For NullSoft Shoutcast Server version 1.9.2, consider restricting the length of server names and URLs to prevent exploitation until a patch is available. As a temporary workaround, monitor server resources closely to quickly identify and respond to potential denial of service attempts.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1174

Affected Products

Nullsoft Shoutcast Server