Fedora Account System
Red Hat Associate
Red Hat Customer
Multiple buffer overflows in src/ezstream.c in Ezstream before 0.3.0 allow remote attackers to execute arbitrary code via a crafted XML configuration file processed by the (1) urlParse function, which causes a stack-based overflow and the (2) ReplaceString function, which causes a heap-based overflow. References: https://exchange.xforce.ibmcloud.com/vulnerabilities/32867
All Fedoras deliver 1.0.2. The only EPEL EPEL-7 delivers 0.6.0. I do not buy the "remote attacker" story because ezstream does not retrieve any configuration files over a network. It's always a local user.