DEBIAN-CVE-2015-3026

Source
https://security-tracker.debian.org/tracker/CVE-2015-3026
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2015-3026.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2015-3026
Published
2015-04-29T20:59:02.123Z
Modified
2025-11-14T04:01:09.498563Z
Summary
[none]
Details

Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as demonstrated by a request to "admin/killsource?mount=/test.ogg."

References

Affected packages

Debian:11 / icecast2

Package

Name
icecast2
Purl
pkg:deb/debian/icecast2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / icecast2

Package

Name
icecast2
Purl
pkg:deb/debian/icecast2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / icecast2

Package

Name
icecast2
Purl
pkg:deb/debian/icecast2?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}