PT-2003-2126 · Nullsoft · Nullsoft Shoutcast Server
Published
2003-12-31
·
Updated
2017-07-11
·
CVE-2003-1174
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
NullSoft Shoutcast Server version 1.9.2
Description
The issue allows local users to cause a denial of service. This can be achieved via two methods: (1) by using
icy-name followed by a long server name, or (2) by using icy-url followed by a long URL.Recommendations
For NullSoft Shoutcast Server version 1.9.2, consider restricting the length of server names and URLs to prevent exploitation until a patch is available. As a temporary workaround, monitor server resources closely to quickly identify and respond to potential denial of service attempts.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nullsoft Shoutcast Server