Gentoo Archives: gentoo-announce

From: Thierry Carrez <koon@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200405-10 ] Icecast denial of service vulnerability
Date: Wed, 19 May 2004 17:49:15
Message-Id: 40AB9DD1.7020701@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
5 Gentoo Linux Security Advisory GLSA 200405-10
6 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
7 http://security.gentoo.org/
8 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
9
10 Severity: Normal
11 Title: Icecast denial of service vulnerability
12 Date: May 19, 2004
13 Bugs: #50935
14 ID: 200405-10
15
16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
17
18 Synopsis
19 ========
20
21 Icecast is vulnerable to a denial of service attack allowing remote
22 users to crash the application.
23
24 Background
25 ==========
26
27 Icecast is a program that streams audio data to listeners over the
28 Internet.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 net-misc/icecast <= 2.0.0 >= 2.0.1
37
38 Description
39 ===========
40
41 There is an out-of-bounds read error in the web interface of Icecast
42 when handling Basic Authorization requests. This vulnerability can
43 theorically be exploited by sending a specially crafted Authorization
44 header to the server.
45
46 Impact
47 ======
48
49 By exploiting this vulnerability, it is possible to crash the Icecast
50 server remotely, resulting in a denial of service attack.
51
52 Workaround
53 ==========
54
55 There is no known workaround at this time. All users are advised to
56 upgrade to the latest available version of Icecast.
57
58 Resolution
59 ==========
60
61 All users of Icecast should upgrade to the latest stable version:
62
63 # emerge sync
64
65 # emerge -pv ">=net-misc/icecast-2.0.1"
66 # emerge ">=net-misc/icecast-2.0.1"
67
68 References
69 ==========
70
71 [ 1 ] Icecast 2.0.1 announcement
72 http://www.xiph.org/archives/icecast/7144.html
73
74 Availability
75 ============
76
77 This GLSA and any updates to it are available for viewing at
78 the Gentoo Security Website:
79
80 http://security.gentoo.org/glsa/glsa-200405-10.xml
81
82 Concerns?
83 =========
84
85 Security is a primary focus of Gentoo Linux and ensuring the
86 confidentiality and security of our users machines is of utmost
87 importance to us. Any security concerns should be addressed to
88 security@g.o or alternatively, you may file a bug at
89 http://bugs.gentoo.org.
90
91 License
92 =======
93
94 Copyright 2004 Gentoo Technologies, Inc; referenced text
95 belongs to its owner(s).
96
97 The contents of this document are licensed under the
98 Creative Commons - Attribution / Share Alike license.
99
100 http://creativecommons.org/licenses/by-sa/1.0
101
102 -----BEGIN PGP SIGNATURE-----
103 Version: GnuPG v1.2.4 (GNU/Linux)
104 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
105
106 iD8DBQFAq53RvcL1obalX08RAqcNAJ4gZ4YdpevFjkRpLI5T2k7X/V7swACdGDOZ
107 ZJxICcqzvaB5M8+ZvEMoWdQ=
108 =kl6m
109 -----END PGP SIGNATURE-----