Icecast XSL allows elevated privileges
| icecast-xsl-gain-pivileges (19753) |
Description:
Icecast could allow a local attacker to gain elevated privileges, caused by a vulnerability in the XSL parser. A local attacker could create a specially-crafted XSL file to execute arbitrary code on the system with elevated privileges when loaded onto the system.
Platforms Affected:
- Icecast, Icecast 2.20
Remedy:
No remedy available as of November 29, 2008.
Consequences:
Gain Privileges
References:
- BugTraq Mailing List, Fri Mar 18 2005 - 16:31:14 CST , IceCast up to v2.20 multiple vulnerabilities at http://archives.neohapsis.com/archives/bugtraq/2005-03/0331.html.
- Icecast Web site, Icecast at http://www.icecast.org/.
- BID-12849: Icecast XSL Parser Multiple Vulnerabilities
- CVE-2005-0838: Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via (1) a long test value in an xsl:when tag, (2) a long test value in an xsl:if tag, or (3) a long select value in an xsl:value-of tag.
- SECTRACK ID: 1013475: Icecast XSL Parser Lets Local Users Gain Elevated Privileges and Discloses XSL Files to Remote Users
Reported:
Mar 19, 2005
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
