First published: Tue Mar 22 2005(Updated: )
IceCast 2.20 allows remote attackers to bypass the XSL parser and obtain the source for XSL files via a request for a .xsl file with a trailing . (dot).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Hazelcast Jet | =2.0 | |
Hazelcast Jet | =2.0.1 | |
Hazelcast Jet | =2.0.2 | |
Hazelcast Jet | =2.1.0 | |
Hazelcast Jet | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0837 is considered a medium severity vulnerability as it allows attackers to bypass security measures.
To fix CVE-2005-0837, it is recommended to upgrade IceCast to a version that is not affected by this vulnerability.
CVE-2005-0837 affects IceCast versions 2.0, 2.0.1, 2.0.2, 2.1.0, and 2.2.
Yes, CVE-2005-0837 can lead to information disclosure by allowing attackers to access the source of XSL files.
There is no widely published workaround for CVE-2005-0837, so upgrading to a secure version is the best practice.