CVE-2002-1982: Medium severity Icecast Icecast vulnerability
Directory traversal vulnerability in the listdirectory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a .. (dot dot) in the GET request, which returns different error messages depending on whether the directory exists or not.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1982?
The severity of CVE-2002-1982 is considered to be low, as it allows directory existence checks rather than direct exploitation.
How do I fix CVE-2002-1982?
To fix CVE-2002-1982, upgrade to a more recent version of Icecast that does not include this vulnerability.
What systems are impacted by CVE-2002-1982?
CVE-2002-1982 specifically affects Icecast version 1.3.12.
What exploitation risks are associated with CVE-2002-1982?
The exploitation risk of CVE-2002-1982 primarily involves information disclosure through directory existence checks.
Can CVE-2002-1982 be exploited remotely?
Yes, CVE-2002-1982 can be exploited remotely by sending crafted GET requests to the Icecast server.