Icecast Server Slash File Name...

- AV AC AU C I A
发布: 2001-06-26
修订: 2025-04-13

Icecast is an open source audio-streaming server for both Unix and Microsoft Windows systems. Icecast does not sufficiently sanitize user-supplied input, or sanely handle unexpected input. Upon receiving a request from a user for a file that ends with a slash or period, the server will crash. The behaviour occurs when the remote attacker adds an '/', '\' or '.' to the end the URL they craft to request the file. The request of an existing file is not necessary, as the Icecast server will fail regardless.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息