20020402 icecast 1.3.11 remote shell/root exploit - #tempmailing list
http://marc.info/?l=bugtraq&m=101780890326179&w=2 CVE-2002-0177
Icecast 1.x - AVLLib Buffer Overflow
Record summary
CVE-2002-0177 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request from an MP3 client.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBIcecast 1.x - AVLLib Buffer OverflowExploitDB exploitby dizznuttNot analyzed1 file
References
720020403 Icecast temp patch (OR: Patches? We DO need stinkin' patches!!@$!)mailing list
http://marc.info/?l=bugtraq&m=101786838300906&w=2 20020404 Full analysis of multiple remotely exploitable bugs in Icecast 1.3.11mailing list
http://marc.info/?l=bugtraq&m=101793704306035&w=2 VU#596387Third-party advisory
http://www.kb.cert.org/vuls/id/596387 4415vdb entry
http://www.securityfocus.com/bid/4415 xiph.orgConfirmation
http://www.xiph.org/archives/icecast/2616.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0177