A new vulnerability has been discovered in the Icecast streaming platform, which could be exploited to terminate the live broadcast of any station using the platform. The vulnerability is on the server side, and is caused by improper permissions. When exploited, the server crashes, and the broadcast is interrupted. In theory, there is also the possibility of remote code execution. To exploit the vulnerability, a hacker would have to send specially crafted HTTP headers to the server that appear to be significantly larger than usual.

Icecast is maintained by the Xiph.org, and is a service through which it is possible to broadcast video and audio. As it is available under a free software license, and supports open communication standards, it is a fairly popular service that is mainly used for broadcasting online radio stations.
In the latest patch that has been released, the problem seems to have been resolved. In the changelogs, the vulnerability is described as a buffer overflow and affects versions 2.4.0, 2.4.1, 2.4.2 and 2.4.3.
The security bug comes from the snprintf function which redirects output to a buffer. However, this mode of operation does not offer any security, and with certain techniques it can cause problems. Nick Rolfe from the Semmle Security Research Teamreports that the snprintf function causes a buffer overflow if the size argument is larger than the size of the buffer.
The vulnerability is no longer exploitable, as Icecast version 2.4.4 was released on November 1. It is codenamed CVE-2018-18820 and a proof of concept exploit has been published since October 16.
