CVE-2018-18820
Gentoo Linux Security Advisory 201811-09
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted header, leading to denial of service and potentially remote code execution.
Se ha descubierto un desbordamiento de búfer en el backend de autenticación de URL en Icecast en versiones anteriores a la 2.4.4. Si el backend está habilitado, cualquier cliente HTTP malicioso puede enviar una petición para ese recurso concreto incluyendo una cabecera manipulada, lo que conduce a una denegación de servicio y a la potencial ejecución remota de código.
Nick Rolfe discovered multiple buffer overflows in the Icecast multimedia streaming server which could result in the execution of arbitrary code.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-10-29 CVE Reserved
- 2018-11-04 CVE Published
- 2024-08-05 CVE Updated
- 2025-02-02 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1042019 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2018/11/msg00033.html | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://github.com/impulsiveness/CVE-2018-18820 | 2025-02-02 |
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2018/11/01/3 | 2019-01-23 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/201811-09 | 2019-01-23 | |
https://www.debian.org/security/2018/dsa-4333 | 2019-01-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xiph Search vendor "Xiph" | Icecast Search vendor "Xiph" for product "Icecast" | < 2.4.4 Search vendor "Xiph" for product "Icecast" and version " < 2.4.4" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|