PT-2009-2829 · Kde · Amarok
Jan Lieskovsky
·
Published
2009-01-16
·
Updated
2018-10-11
·
CVE-2009-0136
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Amarok versions 1.4.10 through 2.0.1
Description
The issue concerns multiple array index errors in the Audible::Tag::readTag function, which can be exploited by remote attackers using a crafted Audible Audio (.aa) file. This can lead to a denial of service (application crash) or the execution of arbitrary code. The exploitation is possible through the
nlen or vlen Tag value, resulting in an invalid pointer dereference or the writing of a 0x00 byte to an arbitrary memory location after an allocation failure.Recommendations
For Amarok versions 1.4.10 through 2.0.1, consider disabling the Audible::Tag::readTag function or restricting the use of Audible Audio (.aa) files until a patch is available. Avoid using the
nlen or vlen Tag values in the affected function to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amarok