CVE-2004-1561
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 78%
from disclosure to weapon0 days
Published on NVDFeb 20
1st PoCOct 6
metasploitSep 28
exploitation probability
78%top 1% of all CVEs
observed exploitation
nono source reports it
9 public exploit(s)
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers.
Affected products
n/a · n/apublic PoCs found — 9✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/568exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/16763exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/573githubgithub.com/ivanitlearning/CVE-2004-1561★ 7githubgithub.com/thel1nus/CVE-2004-1561-Notes★ 3githubgithub.com/darrynb89/CVE-2004-1561★ 1githubgithub.com/Danyw24/CVE-2004-1561-Icecast-Header-Overwrite-buffer-overflow-RCE-2.0.1-Win32-★ 0githubgithub.com/MonseigneurPatas/thm-ice-icecast-rce-privesc★ 0githubgithub.com/ratiros01/CVE-2004-1561★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://aluigi.altervista.org/adv/iceexec-adv.txthttp://marc.info/?l=bugtraq&m=109640005127644&w=2http://marc.info/?l=bugtraq&m=109674593230539&w=2http://secunia.com/advisories/12666/http://securitytracker.com/id?1011439https://exchange.xforce.ibmcloud.com/vulnerabilities/17538http://www.osvdb.org/10446http://www.securiteam.com/exploits/6X00315BFM.htmlhttp://www.securityfocus.com/bid/11271