Required CVE Record Information
Description
Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors.
References 6 Total
- seclists.org: [oss-security] 20141125 Re: Re: CVE request: icecast: possible leak of on-connect scripts mailing-list
- https://bugzilla.redhat.com/show_bug.cgi?id=1168146
- https://trac.xiph.org/changeset/19137/
- http://icecast.org/news/icecast-release-2_4_0/
- seclists.org: [oss-security] 20141126 Re: CVE request: icecast: possible leak of on-connect scripts mailing-list
- lists.opensuse.org: openSUSE-SU-2014:1591 vendor-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 6 Total
- seclists.org: [oss-security] 20141125 Re: Re: CVE request: icecast: possible leak of on-connect scripts mailing-listx_transferred
- https://bugzilla.redhat.com/show_bug.cgi?id=1168146 x_transferred
- https://trac.xiph.org/changeset/19137/ x_transferred
- http://icecast.org/news/icecast-release-2_4_0/ x_transferred
- seclists.org: [oss-security] 20141126 Re: CVE request: icecast: possible leak of on-connect scripts mailing-listx_transferred
- lists.opensuse.org: openSUSE-SU-2014:1591 vendor-advisoryx_transferred