Total vulnerabilities in the database
Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as demonstrated by a request to "admin/killsource?mount=/test.ogg."
Software | From | Fixed in |
---|---|---|
xiph / icecast | - | 2.4.1.x |
debian / debian_linux | 8.0 | 8.0.x |
opensuse / opensuse | 13.1 | 13.1.x |
opensuse / opensuse | 13.2 | 13.2.x |