Icecast before 2.4.1 transmits the output of the on-connect script, which might allow remote attackers to obtain sensitive information, related to shared file descriptors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2014/11/19/23 | mailing list exploit |
http://www.mandriva.com/security/advisories?name=MDVSA-2014:231 | vendor advisory |
http://icecast.org/news/icecast-release-2_4_1/ | |
https://trac.xiph.org/ticket/2087 | exploit |
http://lists.opensuse.org/opensuse-updates/2014-12/msg00038.html | vendor advisory |
http://www.securityfocus.com/bid/71312 | vdb entry |
https://trac.xiph.org/ticket/2089 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/98991 | vdb entry |
http://www.openwall.com/lists/oss-security/2014/11/20/22 | mailing list exploit |