Vulnerabilities > CVE-2005-0837 - Multiple vulnerability in Icecast XSL Parser

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
icecast
nessus

Summary

IceCast 2.20 allows remote attackers to bypass the XSL parser and obtain the source for XSL files via a request for a .xsl file with a trailing . (dot).

Nessus

NASL familyCGI abuses
NASL idICECAST_XSL_PARSER_FLAWS.NASL
descriptionThe remote host is running a version of Icecast that suffers from two flaws in its XSL parser. - A Locally-Exploitable Buffer Overflow Vulnerability The XSL parser does not check the size of XSL
last seen2020-06-01
modified2020-06-02
plugin id17592
published2005-03-22
reporterThis script is Copyright (C) 2005-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/17592
titleIcecast XSL Parser Multiple Vulnerabilities (OF, ID)