RULE(RULE ID:324097)

Rule General Information
Release Date: 2020-01-19
Rule Name: Icecast stream_auth handler Denial of Service Vulnerability (CVE-2015-3026)
Severity:
CVE ID:
Rule Protection Details
Description: Icecast before 2.4.2, when a stream_auth handler is defined for URL authentication, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a request without login credentials, as demonstrated by a request to "admin/killsource?mount=/test.ogg."
Impact: An attacker can launch a denial of service attack by exploiting the vulnerability successfully.
Affected OS: Windows, Others
Reference: SecurityFocusBID:73965
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163859.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/164061.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/164074.html
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://downloads.xiph.org/releases/icecast/