Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in . (dot), / (forward slash), or \ (backward slash).
Link | Tags |
---|---|
http://www.redhat.com/support/errata/RHSA-2002-063.html | vendor advisory |
http://www.debian.org/security/2001/dsa-089 | vendor advisory |
http://www.securityfocus.com/archive/1/193516 | mailing list exploit vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6751 | vdb entry |
http://www.icecast.org/index.html | |
http://www.redhat.com/support/errata/RHSA-2001-105.html | vendor advisory |
http://www.securityfocus.com/bid/2933 | exploit vdb entry patch vendor advisory |
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-020.0.txt | vendor advisory |
http://www.icecast.org/releases/icecast-1.3.11.tar.gz |