First published: Wed Nov 26 2014(Updated: )
Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/icecast | <2.4.0 | 2.4.0 |
Icecast | <=2.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9091 is considered a high severity vulnerability due to the potential for local privilege escalation.
To fix CVE-2014-9091, upgrade to Icecast version 2.4.0 or later.
The main impact of CVE-2014-9091 is that local users may gain elevated privileges which could compromise system security.
CVE-2014-9091 affects Icecast versions prior to 2.4.0, including all versions up to 2.3.3.
CVE-2014-9091 can potentially be exploited by local users, making it a concern in multi-user environments.