Vulnerability record · CVE-2004-1373 · published 23 December 2004
CVE-2004-1373: SHOUTcast format string flaw allows code execution
Nullsoft · Shoutcast Server
SHOUTcast 1.9.4 contains a format string vulnerability reachable through format specifiers placed in a content URL, demonstrated via the filename portion of an .mp3 file. Successful abuse can crash the server or allow arbitrary code execution, making it a serious risk for any internet-facing SHOUTcast deployment.
Description
Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a content URL, as demonstrated in the filename portion of a .mp3 file.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with a very high EPSS score, though the product is legacy and no KEV listing exists.
What it is
SHOUTcast 1.9.4 contains a format string vulnerability reachable through format specifiers placed in a content URL, demonstrated via the filename portion of an .mp3 file. Successful abuse can crash the server or allow arbitrary code execution, making it a serious risk for any internet-facing SHOUTcast deployment.
Impact
An attacker can crash the SHOUTcast server (denial of service) and potentially execute arbitrary code in the server's context, gaining control of the streaming host.
Attack surface
Reachable remotely over the network with no authentication and no user interaction, per the AV:N/AC:L/Au:N vector; the malicious input is delivered through a content URL, specifically the .mp3 filename portion.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded, but EPSS is very high (0.70066, 99.3rd percentile), indicating strong predicted exploitation activity; references include patch-tagged advisories.
What to do
- Upgrade SHOUTcast to a version that fixes the format string flaw; the Gentoo GLSA and SecurityFocus references are tagged as patches.
- If patching is not immediately possible, restrict network access to the SHOUTcast service to trusted clients only.
- Run the SHOUTcast server with least privilege and isolate it from other services to limit code execution impact.
- Monitor vendor and distro advisories for updated packages covering this issue.
Detection
- Inspect SHOUTcast and web logs for requests containing format string specifiers such as %n, %s or %x in URLs or .mp3 filenames.
- Alert on SHOUTcast process crashes or unexpected restarts that correlate with unusual URL requests.
- Watch for anomalous child processes or outbound connections spawned by the SHOUTcast service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-1373 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-1373), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.