amarok: multiple buffer overflows when parsing Audible .aa files
Published Jan 16, 2009
9.3
HIGHCVSS 2.0
EPSS 6.66%
Description
Multiple array index errors in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via an Audible Audio (.aa) file with a crafted (1) nlen or (2) vlen Tag value, each of which can lead to an invalid pointer dereference, or the writing of a 0x00 byte to an arbitrary memory location, after an allocation failure.
Affected products
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.66% (0.06656) | 93.68th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.26% (0.06261) | 92.64th | v5 (v2026.06.15) |
| May 28, 2025 | 16.10% (0.16097) | 94.44th | v4 (v2025.03.14) |
| Mar 19, 2025 | 12.41% (0.12412) | 93.03th | v4 (v2025.03.14) |
| Mar 17, 2025 | 10.45% (0.10450) | 92.67th | v4 (v2025.03.14) |
| Dec 17, 2024 | 14.95% (0.14952) | 95.80th | v3 (v2023.03.01) |
| Jun 5, 2023 | 11.83% (0.11835) | 94.47th | v3 (v2023.03.01) |
| Apr 21, 2023 | 10.72% (0.10718) | 94.17th | v3 (v2023.03.01) |
| Mar 7, 2023 | 13.30% (0.13295) | 94.62th | v3 (v2023.03.01) |
| Mar 6, 2023 | 6.60% (0.06604) | 91.53th | v2 (v2022.01.01) |
| Apr 1, 2022 | 6.60% (0.06604) | 90.72th | v2 (v2022.01.01) |
| Feb 4, 2022 | 6.60% (0.06604) | 78.62th | v2 (v2022.01.01) |
References (29)
- http://amarok.kde.org/en/releases/2.0.1.1 x_refsource_CONFIRMVendor Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=254896 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00000.html vendor-advisoryx_refsource_SUSE
- http://openwall.com/lists/oss-security/2009/01/14/2 mailing-listx_refsource_MLIST
- http://secunia.com/advisories/33505 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/33522 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33640 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33819 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34315 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34407 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200903-34.xml vendor-advisoryx_refsource_GENTOO
- http://securityreason.com/securityalert/4915 third-party-advisoryx_refsource_SREASON
- http://trapkit.de/advisories/TKADV2009-002.txt x_refsource_MISCExploit
- http://websvn.kde.org/?view=rev&revision=908391 x_refsource_CONFIRM
- http://websvn.kde.org/?view=rev&revision=908401 x_refsource_CONFIRM
- http://websvn.kde.org/?view=rev&revision=908415 x_refsource_CONFIRM
- http://www.debian.org/security/2009/dsa-1706 vendor-advisoryx_refsource_DEBIAN
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:030 vendor-advisoryx_refsource_MANDRIVA
- http://www.securityfocus.com/archive/1/499984/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/33210 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1021558 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-739-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2009/0100 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2009-0136 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=479560 x_refsource_CONFIRMIssue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=479946 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2009-0136
- https://www.cve.org/CVERecord?id=CVE-2009-0136
- https://www.redhat.com/archives/fedora-package-announce/2009-January/msg00708.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.