Icecast: Arbitrary code execution A vulnerability in Icecast might allow remote attackers to execute arbitrary code. Icecast 2018-11-10 2018-11-10 670148 remote 2.4.4 2.4.4

Icecast is an open source alternative to SHOUTcast that supports MP3, OGG (Vorbis/Theora) and AAC streaming.

Multiple buffer overflows have been discovered in Icecast. Please review the CVE identifier referenced below for details.

A remote attacker, by sending a specially crafted request using authentication type “url”, could possibly execute arbitrary code with the privileges of the process, or cause a Denial of Service condition.

There is no known workaround at this time.

All Icecast users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/icecast-2.4.4"
CVE-2018-18820 whissi whissi