Home page logo
/

oss-sec logo oss-sec mailing list archives

Re: Security issue in icecast
From: Moritz Naumann <oss-security () moritz-naumann com>
Date: Mon, 26 Nov 2012 10:35:26 +0100

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi,

I'm not sure it's worth spending your time on this, so please decide
for yourselves:

1. Spelling issue in CVE-2011-4612:

On 12/15/2011 11:25 AM, Jamie Strandboge wrote:
A security bug was reported by Moritz Naumann against icecast in
 Ubuntu.

Details from the public bug follow: 
https://launchpad.net/bugs/894782

From the reporter: "Newline injection in error.log
[..]

The CVE overview now reads:
icecast before 2.3.3 allows remote attackers to inject control 
characters such as newlines into the error loc (error.log) via a 
crafted URL.

I would think "error loc" should actually say "error log".


2. Access complexity

"Low" is correct since specialized access conditions or extenuating
circumstances do not exist and the first three examples provided at
  http://www.first.org/cvss/cvss-guide.html#i2.1.2
do apply.

Thanks,

Moritz Naumann
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iQIcBAEBCgAGBQJQszfAAAoJEL2W7K2TRQCwJ6oP/RjTNXSF4H65cDEp3b6Z/y8E
CbF165PSI4j6kqoqtYxY+V9Eu8r7x7czuCjqZTC+DzKxfOi2lb+uWUJ01a5Ldnu1
UX1z210+HOf+XMwDqp3BnaWJwK71ZCIH+9eRkS/6nAWVe04Pk3x5n90fvSJjDvt/
AAbcAtZiiy9Ef81MtK97amHy4GQqR7I1yMQ9BqBV4PB3vGWKp/pIR+bVg3NHbaHp
N4fD9EdKh/LDJDd24Bv9ZKnhp/fumJLwsqkGsJ8ePnqitUxcUZjXUqVTGdhXOmvW
SraEjudIr8Cst6+ykFDkMZYsGe4edhG4MsFFZkmtLvoOsOd4SyuR7jmD58jBSwQj
1fvVaXICmM7mUCeDbdMeJldGzXGoCoEFwBhdBVMvUm4/572CsWzEug9f0QlhqKl4
O1tGG9RuMyD0+5kJ7y1Ay8WdLupPHlUhU+ijFusBIj15+AKa56UCktN41xpvLzUf
c5DO0SBfA9AWcv2+8mxDS752pQ92Cldd6GM3BXtUvmVAeYmn0hDZGev2r1fYCNbl
RrnoOcj0ViSscOd1GsX2vd9u+CE7yvmwu+b7KGuWM6htPCygbT1ntga7YGPZN2P2
utLgPJ6+mwEgJwHzxNECCecfxXOAbWD0mvvXBZIEXxfkY9XV+3ZH2S1/qMH5UBn4
HXYH+XhCcgxI+X42QfDM
=D0i4
-----END PGP SIGNATURE-----


  By Date           By Thread  

Current thread:
  • Re: Security issue in icecast Moritz Naumann (Nov 26)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]