CVE-2011-4612: Input Validation
Published Nov 20, 2012
·Updated
icecast before 2.3.3 allows remote attackers to inject control characters such as newlines into the error loc (error.log) via a crafted URL.
Affected Software
1 affected component
xiph Icecast<=2.3.2
Remediation
Patch Available
Event History
Nov 20, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4612?
CVE-2011-4612 is classified as a medium severity vulnerability due to its potential for remote exploitation.
2
How do I fix CVE-2011-4612?
To fix CVE-2011-4612, upgrade Icecast to version 2.3.3 or later.
3
What types of attacks are possible with CVE-2011-4612?
CVE-2011-4612 allows remote attackers to perform log injection attacks by injecting control characters into error logs.
4
Which versions of Icecast are affected by CVE-2011-4612?
CVE-2011-4612 affects Icecast versions prior to 2.3.3.
5
Can CVE-2011-4612 lead to further exploits on the system?
Yes, CVE-2011-4612 can potentially lead to further exploits if attackers manipulate the error logs for malicious purposes.