CVE-2011-4612

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
20/11/2012
Last modified:
11/04/2025

Description

icecast before 2.3.3 allows remote attackers to inject control characters such as newlines into the error loc (error.log) via a crafted URL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:xiph:icecast:*:*:*:*:*:*:*:* 2.3.2 (including)