CVE-2002-0177

icecast <= 1.3.11 - Remote Code Execution via Long HTTP GET Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0177. PoCs published by dizznutt.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Icecast versions up to 1.3.11. It sends a crafted HTTP GET request to overflow the stack and execute arbitrary shellcode, resulting in remote code execution with the privileges of the Icecast server.

Description

Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request from an MP3 client.

Exploits (1)

exploitdb WORKING POC VERIFIED
by dizznutt · cremoteunix
https://www.exploit-db.com/exploits/21363

This exploit targets a buffer overflow vulnerability in Icecast versions up to 1.3.11. It sends a crafted HTTP GET request to overflow the stack and execute arbitrary shellcode, resulting in remote code execution with the privileges of the Icecast server.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Icecast up to 1.3.11
No auth needed
Prerequisites: Network access to the Icecast server · Icecast server running on a vulnerable version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=101780890326179&w=2
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/596387
Patch, Vendor Advisory x_refsource_confirm
http://www.xiph.org/archives/icecast/2616.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4415
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=101786838300906&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=101793704306035&w=2

Scores

EPSS 0.0955
EPSS Percentile 94.8%

Details

Status published
Products (4)
icecast/icecast 1.3.7
icecast/icecast 1.3.8_beta2
icecast/icecast 1.3.10
icecast/icecast 1.3.11
Published Apr 22, 2002
Tracked Since Feb 18, 2026