5
CVSSv2

CVE-2015-3026

Published: 29/04/2015 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Icecast prior to 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote malicious users to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as demonstrated by a request to "admin/killsource?mount=/test.ogg."

Vulnerable Product Search on Vulmon Subscribe to Product

xiph icecast

debian debian linux 8.0

opensuse opensuse 13.2

opensuse opensuse 13.1

Vendor Advisories

Debian Bug report logs - #782120 icecast2: icecast can be remotely killed by anyone if using <authentication type="url"> and stream_auth option (CVE-2015-3026) Package: icecast2; Maintainer for icecast2 is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for icecast2 is src:icecast2 (PTS, buildd, popc ...