A buffer overflow was discovered in the URL-authentication backend of the icecast2, the popular open source streaming media server. If the backend is enabled, then any malicious HTTP client can send a request . Package : icecast2 Version : 2.4.0-1.1+deb8u2 CVE ID : CVE-2018-18820 Debian Bug : 912611 A buffer overflow was discovered in the URL-authentication backend of the icecast2, the popular open source streaming media server. If the backend is enabled, then any malicious HTTP client can send a request for specific resource including a crafted header which can overwrite the server's stack contents, leading to denial of service and potentially remote code execution. For Debian 8 "Jessie", this problem has been fixed in version 2.4.0-1.1+deb8u2. We recommend that you upgrade your icecast2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Uncover the DLA-1588-1 alert concerning Icecast2 that resolves a buffer overflow vulnerability impacting Debian Jessie.. Icecast2 Security Update, Buffer Overflow, Debian Advisory, Denial of Service. . Severity: Important. LinuxSecurity.com Team
Nick Rolfe discovered multiple buffer overflows in the Icecast multimedia streaming server which could result in the execution of arbitrary code. For the stable distribution (stretch), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4333-1
Juliane Holzt discovered that Icecast2, a streaming media server, could dereference a NULL pointer when URL authentication is configured and the stream_auth URL is trigged by a client without setting any credentials. This could allow remote attackers to cause a denial of service (crash). . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3239-1
Get the latest Linux and open source security news straight to your inbox.