Icecast before 2.4.0 does not change the supplementary group privileges when is configured, which allows local users to gain privileges via unspecified vectors.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9091
Reference (s):
- http://icecast.org/news/icecast-release-2_4_0/
- https://bugzilla.redhat.com/show_bug.cgi?id=1168146
- https://trac.xiph.org/changeset/19137/
- MLIST:[oss-security] 20141125 Re: Re: CVE request: icecast: possible leak of on-connect scripts
- URL: http://seclists.org/oss-sec/2014/q4/794