CVE-2018-18820

high-risk
Published 2018-11-05

A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted header, leading to denial of service and potentially remote code execution.

Do I need to act?

!
66.2% chance of exploitation in next 30 days
EPSS score — higher than 34% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.1/10 High
NETWORK / HIGH complexity

Affected Products (3)

Affected Vendors

52
/ 100
high-risk
Severity 24/34 · High
Exploitability 19/34 · Moderate
Exposure 9/34 · Low