Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Mageia 6: 2018-0472 Critical: Icecast Buffer Overflow Alert

mageia
Calendar Grey November 28, 2018
Dist Mageia Esm H88
Icecast's URL authentication flaw enables remote code execution due to buffer overflows. Ensure you update the package to mitigate this security risk.
Buffer overflows in URL auth code if there is a "mount" definition that enables URL authentication

Summary

Buffer overflows in URL auth code if there is a "mount" definition that enables URL authentication. A malicious client could send long HTTP headers, leading to a buffer overflow and potential remote code execution (CVE-2018-18820).

References

- https://bugs.mageia.org/show_bug.cgi?id=23798

- https://www.openwall.com/lists/oss-security/2018/11/01/3

- https://www.cve.org/CVERecord?id=CVE-2018-18820

Resolution

SRPMS

- 6/core/icecast-2.4.4-1.mga6

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 28 Nov 2018
URL: https://advisories.mageia.org/MGASA-2018-0472.html
Type: security
CVE: CVE-2018-18820

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here