Critical Flaw In SHOTcast

Filed under: — By Aviran Mordo @ 1:41 pm

SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a content URL, as demonstrated in the filename portion of a .mp3 file.

SHOUTcast is Nullsoft’s Free Winamp-based distributed streaming audio system.

French Security Incident Response Team rates this vulnerability as critical and recommend that you upgrade to version 1.9.5


Leave a Reply

You must have Javascript enabled in order to submit comments.

All fields are optional (except comment).
Some comments may be held for moderation (depends on spam filter) and not show up immediately.
Links will automatically get rel="nofollow" attribute to deter spammers.

Powered by WordPress