From 6ed5232306378508abfe01c66657a2b61f535c0b Mon Sep 17 00:00:00 2001 From: Josef El-Rayes Date: Thu, 14 Oct 2004 16:55:27 +0000 Subject: [PATCH] Document two seperate security vulnerabilities in icecast1 and icecast2. Approved by: nectar --- security/vuxml/vuln.xml | 55 ++++++++++++++++++++++++++++++++++++++--- 1 file changed, 52 insertions(+), 3 deletions(-) diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 1d4881f2f865..b8a2af85236e 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -32,6 +32,56 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --> + + icecast -- Cross-Site Scripting Vulnerability + + + icecast + 1.3.12_2 + + + + +

Caused by improper filtering of HTML code in the + status display, it is possible for a remote user + to execute scripting code in the target user's + browser.

+ +
+ + CAN-2004-0781 + http://www.securitytracker.com/alerts/2004/Aug/1011047.html + + + 2004-08-24 + 2004-10-13 + +
+ + + icecast -- HTTP header overflow + + + icecast2 + 2.0.2,1 + + + + +

It is possible to execute remote code simply using + HTTP request plus 31 headers followed by a shellcode that will be + executed directly.

+ +
+ + http://marc.theaimsgroup.com/?l=full-disclosure&m=109646043512722 + + + 2004-09-29 + 2004-10-13 + +
+ freeradius -- denial-of-service vulnerability @@ -59,10 +109,10 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. - xerces-c2 -- Attribute blowup denial-of-service + xerces_c -- Attribute blowup denial-of-service - xerces-c2 + xerces_c 2.6.0 @@ -85,7 +135,6 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 2004-10-02 2004-10-13 - 2004-10-14