CVE-2014-9091: Icecast

Medium severity, CVSS 4.6. EPSS: 0.5% chance of exploitation in the next 30 days.

Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors.

Affected products

  • Icecast Icecast: up to and including 2.3.3

Published 2014-12-10. Last modified 2026-06-17.