CVE-2002-0177 describes buffer overflow vulnerabilities in Icecast versions 1.3.11 and earlier. Remote attackers can exploit this by sending a crafted, long HTTP GET request from an MP3 client, potentially leading to arbitrary code execution. The vulnerability has a CVSS score of 7.5, indicating high severity with network-based exploitation, low attack complexity, and potential for partial impact on confidentiality, integrity, and availability. While not listed on the KEV catalog, an ExploitDB entry (EDB-21363) exists for an AVLLib buffer overflow, suggesting public exploit code availability, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.7CPE matchmatch criteria | cpe:2.3:a:icecast:icecast:1.3.7:*:*:*:*:*:*:* | ||
1.3.8_beta2CPE matchmatch criteria | cpe:2.3:a:icecast:icecast:1.3.8_beta2:*:*:*:*:*:*:* | ||
1.3.10CPE matchmatch criteria | cpe:2.3:a:icecast:icecast:1.3.10:*:*:*:*:*:*:* | ||
1.3.11CPE matchmatch criteria | cpe:2.3:a:icecast:icecast:1.3.11:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.