CVE-2009-0135 describes multiple integer overflow vulnerabilities in the Audible::Tag::readTag function within Amarok versions 1.4.10 through 2.0.1. These flaws allow remote attackers to execute arbitrary code by crafting malicious Audible Audio (.aa) files with large nlen or vlen Tag values, leading to heap-based buffer overflows. With a CVSS score of 9.3, this vulnerability is critical, requiring no authentication and moderate attack complexity, but potentially granting full confidentiality, integrity, and availability compromise. Despite its high severity, there is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.10CPE matchmatch criteria | cpe:2.3:a:amarok:amarok:1.4.10:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:amarok:amarok:2.0:*:*:*:*:*:*:* | ||
2.0.1CPE matchmatch criteria | cpe:2.3:a:amarok:amarok:2.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.