Lucene search

K
cveMitreCVE-2004-1373
HistoryJan 19, 2005 - 5:00 a.m.

CVE-2004-1373

2005-01-1905:00:00
mitre
web.nvd.nist.gov
30
cve
2004
1373
format string vulnerability
shoutcast
denial of service
application crash
execute arbitrary code
remote attackers
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.972

Percentile

99.8%

Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a content URL, as demonstrated in the filename portion of a .mp3 file.

Affected configurations

Nvd
Node
nullsoftshoutcast_serverMatch1.9.4linux
OR
nullsoftshoutcast_serverMatch1.9.4mac_os_x
OR
nullsoftshoutcast_serverMatch1.9.4win32
VendorProductVersionCPE
nullsoftshoutcast_server1.9.4cpe:2.3:a:nullsoft:shoutcast_server:1.9.4:*:linux:*:*:*:*:*
nullsoftshoutcast_server1.9.4cpe:2.3:a:nullsoft:shoutcast_server:1.9.4:*:mac_os_x:*:*:*:*:*
nullsoftshoutcast_server1.9.4cpe:2.3:a:nullsoft:shoutcast_server:1.9.4:*:win32:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.972

Percentile

99.8%