Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 65678 - Icecast 2.0.2 contains exploit (unknown?)
Summary: Icecast 2.0.2 contains exploit (unknown?)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High enhancement (vote)
Assignee: Gentoo Security
URL: http://www.icecast.org
Whiteboard: ? [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2004-09-28 07:20 UTC by Chris White (RETIRED)
Modified: 2011-10-30 22:41 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Chris White (RETIRED) gentoo-dev 2004-09-28 07:20:12 UTC
According to the icecast page, there is a 2.0.2 release which fixed a security
exploit.  That's all they pretty much say, so I'll have to contact upstream
and figure out what it is exactly.  All I know is that 2.0.2 is not in portage
:).
Comment 1 Chris White (RETIRED) gentoo-dev 2004-09-28 07:26:47 UTC
There, found more information:

http://lists.xiph.org/pipermail/icecast-dev/2004-September/001278.html

it seems it's win32 only, but as it says:

but didn't have any noticeable effect on non-win32 
servers..We are recommending that everyone upgrade to icecast 2.0.2 just to 
be sure.

My guess would be to not do anything on this and I'll just bump it to 2.0.2
when I get a chance, but if we want to track this as a security bug just in
case upstream finds out more then we can do that too.  Otherwise re-assign
to sound as a bump request and I'll try and take care of it at some point.
Comment 2 Luke Macken (RETIRED) gentoo-dev 2004-09-28 07:45:44 UTC
We'll hang on to this bug for a bit to see if any non-win32 information leaks out about it.  

Chris/sound, please bump when you get a chance.  Thanks!
Comment 3 Alin Năstac (RETIRED) gentoo-dev 2004-09-29 02:42:54 UTC
http://secunia.com/advisories/12666/

judging after this page, seems it is pretty big.
Comment 4 Chris White (RETIRED) gentoo-dev 2004-09-29 21:29:30 UTC
Ok, the ebuild is bumped in portage.

However, I vote no glsa, as according to all the annoucements I've seen, this
exploit only occurs on win32 systems (as they can tell so far...).  I say close
this out for now, but re-open should something regarding *nix based systems
come up.
Comment 5 Luke Macken (RETIRED) gentoo-dev 2004-09-29 21:38:13 UTC
Closing without GLSA.

Please re-open if any sign of a non-win32 vulnerability arises.