Full analysis of multiple remotely exploitable bugs in Icecast 1.3.11

From: dizznuttat_private
Date: Thu Apr 04 2002 - 05:51:51 PST

  • Next message: Nsfocus Security Team: "NSFOCUS SA2002-02 : Microsoft Windows MUP overlong request kernel overflow"

    Hello,
    
    Attached is a full analysis to accompany the earlier disclosed remote root/shell 
    exploit for the Icecast mp3 streaming server. It also details some other 
    exploitable bugs besides the one that is exploited with the supplied exploit 
    and thus I believe has posting value. This write-up was mainly meant to 
    aid the icecast developers in locating and eliminating the exact problems,
     but I can imagine it would be of some value to other interested parties 
    as well.
    
    ltr,
    diz - #temp
    
    



    This archive was generated by hypermail 2b30 : Thu Apr 04 2002 - 08:21:18 PST