icecast2 2.3.3-2ubuntu1.14.04.1 source package in Ubuntu

Changelog

icecast2 (2.3.3-2ubuntu1.14.04.1) trusty-security; urgency=high

  * SECURITY UPDATE: Denial of service vulnerability.
    - d/p/0002-crash-in-url-auth:
      This fixes a crash (NULL reference) in case URL Auth is used
      and stream_auth is trigged with no credentials passed by the client.
      Username and password is now set to empty strings and transmited to
      the backend server this way.
    - CVE-2015-3026
  * SECURITY UPDATE: Potentially leaks sensitive information.
    - d/p/0001-disconnects_stdio_of_on_dis_connect_scripts:
      Include patchset 19313 (close file handles for external scripts).
    - CVE-2014-9018
  * SECURITY UPDATE: Potentially allows local users to gain
    privileges via unspecified vectors.
    - d/p/0003-override-supplementary-groups:
      In case of <changeowner> only UID and GID were changed,
      supplementary groups were left in place.
      This is a potential security issue only if <changeowner> is used.
      New behaviour is to set UID, GID and set supplementary groups
      based on the UID.
      Even in case of icecast remaining in supplementary group 0
      this "only" gives it things like access to files that are owned
      by group 0 and according to their umask. This is obviously bad,
      but not as bad as UID 0 with all its other special rights.
    - CVE-2014-9091

 -- Unit 193 <email address hidden>  Tue, 28 Apr 2015 17:28:20 -0400

Upload details

Uploaded by:
Unit 193
Sponsored by:
Marc Deslauriers
Uploaded to:
Trusty
Original maintainer:
Ubuntu Developers
Architectures:
any
Section:
sound
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section
Trusty updates universe sound
Trusty security universe sound

Downloads

File Size SHA-256 Checksum
icecast2_2.3.3.orig.tar.gz 1.1 MiB 1b1d06f5f83c9a983cd28cc78aa90e4038f933511b3d20d7fd2cfc116645c36d
icecast2_2.3.3-2ubuntu1.14.04.1.debian.tar.gz 34.2 KiB e8fe11e6a4a79a06cfc000ff5b18bd05748c0c46984120b5a0b5c0b255acecc2
icecast2_2.3.3-2ubuntu1.14.04.1.dsc 2.3 KiB be7655332c2a68dd04704be2322f0828679ef333c7834a685a1393ebc06364b6

View changes file

Binary packages built by this source

icecast2: streaming media server

 Icecast is a versatile multimedia streaming server which can create
 (for instance) a private jukebox or "Internet radio station". It
 supports Ogg streaming using the Vorbis and Theora codecs, as well as
 other formats such as MP3, AAC, or NSV, and is compatible with most
 media players.