CVE-2014-9091 Information
Feb 14, 2021
cve
Description
Icecast before 2.4.0 does not change the supplementary group privileges when changeowner is configured which allows local users to gain privileges via unspecified vectors.
Reference
http://icecast.org/news/icecast-release-2_4_0/ http://lists.opensuse.org/opensuse-updates/2014-12/msg00037.html http://seclists.org/oss-sec/2014/q4/794 http://seclists.org/oss-sec/2014/q4/802 https://bugzilla.redhat.com/show_bug.cgi?id=1168146 https://trac.xiph.org/changeset/19137/
Share on: