PT-2018-14671 · Xiph.Org Foundation+2 · Icecast+2

Nick Rolfe

·

Published

2018-11-04

·

Updated

2024-06-15

·

CVE-2018-18820

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Icecast versions prior to 2.4.4
Description A buffer overflow was discovered in the URL-authentication backend. If the backend is enabled, any malicious HTTP client can send a request for a specific resource including a crafted header, leading to denial of service and potentially remote code execution.
Recommendations For versions prior to 2.4.4, update to version 2.4.4 or later to resolve the issue. As a temporary workaround, consider disabling the URL-authentication backend until a patch is available.

Fix

RCE

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2595
CVE-2018-18820
DLA-1588-1
DSA-4333-1
MGASA-2018-0472
OPENSUSE-SU-2018_3754-1
OPENSUSE-SU-2024:10584-1

Affected Products

Alt Linux
Icecast
Suse