PT-2018-14671 · Xiph.Org Foundation+2 · Icecast+2
Nick Rolfe
·
Published
2018-11-04
·
Updated
2024-06-15
·
CVE-2018-18820
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Icecast versions prior to 2.4.4
Description
A buffer overflow was discovered in the URL-authentication backend. If the backend is enabled, any malicious HTTP client can send a request for a specific resource including a crafted header, leading to denial of service and potentially remote code execution.
Recommendations
For versions prior to 2.4.4, update to version 2.4.4 or later to resolve the issue. As a temporary workaround, consider disabling the URL-authentication backend until a patch is available.
Fix
RCE
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Icecast
Suse