Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.15400
Kategorie:Denial of Service
Titel:ICECast crafted URL DoS
Zusammenfassung:The remote server runs a version of ICECast, an open source streaming audio;server, which is older than version 1.3.11.;;This version is affected by a remote denial of service because Icecast server does not properly sanitize;user-supplied input.;;An remote attacker could send specially crafted URL, by adding '/', '\' or '.' to the end, that may result in a;loss of availability for the service.
Beschreibung:Summary:
The remote server runs a version of ICECast, an open source streaming audio
server, which is older than version 1.3.11.

This version is affected by a remote denial of service because Icecast server does not properly sanitize
user-supplied input.

An remote attacker could send specially crafted URL, by adding '/', '\' or '.' to the end, that may result in a
loss of availability for the service.

Solution:
Upgrade to version 1.3.11 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2001-1083
BugTraq ID: 2933
http://www.securityfocus.com/bid/2933
Bugtraq: 20010626 Advisory (Google Search)
http://www.securityfocus.com/archive/1/193516
Caldera Security Advisory: CSSA-2002-020.0
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-020.0.txt
Debian Security Information: DSA-089 (Google Search)
http://www.debian.org/security/2001/dsa-089
http://www.icecast.org/index.html
http://www.redhat.com/support/errata/RHSA-2001-105.html
http://www.redhat.com/support/errata/RHSA-2002-063.html
XForce ISS Database: icecast-http-remote-dos(6751)
https://exchange.xforce.ibmcloud.com/vulnerabilities/6751
CopyrightCopyright (C) 2004 David Maciejak

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.