First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 50935
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Paul Slinski <deviantgeek@gmail.com>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
koon: ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 50935 depends on: Show dependency tree
Bug 50935 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-05-13 07:01 0000
A vulnerability in Icecast, can be exploited by malicious people to cause a DoS
(Denial of Service).

The vulnerability is caused due to an out-of-bounds read error within the web
interface when handling Basic Authorization requests. This can be exploited to
crash the application by passing a specially crafted, overly long string (about
3000 bytes) in a "Authorization:" header.

The vulnerability has been confirmed in version 2.0.0 for Windows. Other
versions may also be affected.

Reproducible: Always
Steps to Reproduce:
1.
2.
3.




Icecast 2.0.1 has been released to plug the hole

See http://secunia.com/advisories/11578/ for the advisory.

------- Comment #1 From Thierry Carrez (RETIRED) 2004-05-13 08:53:59 0000 -------
Like the Xiph guys say, "this release contains ONLY the fix for this issue" so
it shouldn't be a painful upgrade.

Sound guys, could you bump the ebuild to 2.0.1 ?

------- Comment #2 From Martin Holzer (RETIRED) 2004-05-13 09:24:53 0000 -------
2.0.1 is in cvs

------- Comment #3 From Kurt Lieber 2004-05-13 10:34:00 0000 -------
x86, sparc, amd64, please test/mark stable.

------- Comment #4 From Jon Portnoy (RETIRED) 2004-05-13 10:49:43 0000 -------
Stable on x86 + amd64

------- Comment #5 From Jason Wever (RETIRED) 2004-05-15 12:31:37 0000 -------
Already marked stable on sparc, but tested here and it's good to go.

------- Comment #6 From Thierry Carrez (RETIRED) 2004-05-18 06:49:39 0000 -------
GLSA draft in progress

------- Comment #7 From Thierry Carrez (RETIRED) 2004-05-19 10:49:16 0000 -------
GLSA 200405-10

First Last Prev Next    No search results available      Search page      Enter new bug