Multiple buffer overflows in src/ezstream.c in Ezstream before 0.3.0 allow remote attackers to execute arbitrary code via a crafted XML configuration file processed by the (1) urlParse function, which causes a stack-based overflow and the (2) ReplaceString function, which causes a heap-based overflow. NOTE: some of these details are obtained from third party information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Icecast_ezstream | Xiph | * | 0.1.0 (including) |
Icecast_ezstream | Xiph | * | 0.1.1 (including) |
Icecast_ezstream | Xiph | * | 0.1.2 (including) |
Icecast_ezstream | Xiph | * | 0.1.3 (including) |
Icecast_ezstream | Xiph | * | 0.2.0 (including) |
Icecast_ezstream | Xiph | * | 0.2.1 (including) |