CVE-2005-0837: Medium severity Icecast Icecast vulnerability
Published Mar 22, 2005
·Updated
IceCast 2.20 allows remote attackers to bypass the XSL parser and obtain the source for XSL files via a request for a .xsl file with a trailing . (dot).
Affected Software
5 affected components
Icecast Icecast=2.0
Icecast Icecast=2.0.1
Icecast Icecast=2.0.2
Icecast Icecast=2.1.0
Icecast Icecast=2.2
Event History
Mar 22, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0837?
CVE-2005-0837 is considered a medium severity vulnerability as it allows attackers to bypass security measures.
2
How do I fix CVE-2005-0837?
To fix CVE-2005-0837, it is recommended to upgrade IceCast to a version that is not affected by this vulnerability.
3
Which versions of IceCast are affected by CVE-2005-0837?
CVE-2005-0837 affects IceCast versions 2.0, 2.0.1, 2.0.2, 2.1.0, and 2.2.
4
Can CVE-2005-0837 allow for information disclosure?
Yes, CVE-2005-0837 can lead to information disclosure by allowing attackers to access the source of XSL files.
5
Is there a workaround for CVE-2005-0837?
There is no widely published workaround for CVE-2005-0837, so upgrading to a secure version is the best practice.