Vulnerabilities > CVE-2005-0838 - Multiple vulnerability in Icecast 2.20

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
icecast
nessus
exploit available

Summary

Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via (1) a long test value in an xsl:when tag, (2) a long test value in an xsl:if tag, or (3) a long select value in an xsl:value-of tag.

Vulnerable Configurations

Part Description Count
Application
Icecast
1

Exploit-Db

descriptionIcecast 2.x XSL Parser Multiple Vulnerabilities. CVE-2005-0838. Remote exploits for multiple platform
idEDB-ID:25238
last seen2016-02-03
modified2005-03-18
published2005-03-18
reporterpatrick
sourcehttps://www.exploit-db.com/download/25238/
titleIcecast 2.x - XSL Parser Multiple Vulnerabilities

Nessus

NASL familyCGI abuses
NASL idICECAST_XSL_PARSER_FLAWS.NASL
descriptionThe remote host is running a version of Icecast that suffers from two flaws in its XSL parser. - A Locally-Exploitable Buffer Overflow Vulnerability The XSL parser does not check the size of XSL
last seen2020-06-01
modified2020-06-02
plugin id17592
published2005-03-22
reporterThis script is Copyright (C) 2005-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/17592
titleIcecast XSL Parser Multiple Vulnerabilities (OF, ID)