{
  "modified": "2025-08-09T19:01:27Z",
  "published": "2014-12-10T15:59:19Z",
  "id": "CVE-2014-9091",
  "details": "Icecast before 2.4.0 does not change the supplementary group privileges when \u003cchangeowner\u003e is configured, which allows local users to gain privileges via unspecified vectors.",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://icecast.org/news/icecast-release-2_4_0/"
    },
    {
      "type": "EVIDENCE",
      "url": "https://trac.xiph.org/changeset/19137/"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1168146"
    },
    {
      "type": "WEB",
      "url": "http://lists.opensuse.org/opensuse-updates/2014-12/msg00037.html"
    },
    {
      "type": "WEB",
      "url": "http://seclists.org/oss-sec/2014/q4/794"
    },
    {
      "type": "WEB",
      "url": "http://seclists.org/oss-sec/2014/q4/802"
    }
  ]
}
