CVE-2015-3026
29.04.2015, 20:59
Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as demonstrated by a request to "admin/killsource?mount=/test.ogg."Enginsight
Vendor | Product | Version |
---|---|---|
xiph | icecast | 𝑥 ≤ 2.4.1 |
debian | debian_linux | 8.0 |
opensuse | opensuse | 13.1 |
opensuse | opensuse | 13.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References