Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-0135

Опубликовано: 16 янв. 2009
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Multiple integer overflows in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to execute arbitrary code via an Audible Audio (.aa) file with a large (1) nlen or (2) vlen Tag value, each of which triggers a heap-based buffer overflow.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:amarok:amarok:1.4.10:*:*:*:*:*:*:*
cpe:2.3:a:amarok:amarok:2.0:*:*:*:*:*:*:*
cpe:2.3:a:amarok:amarok:2.0.1:*:*:*:*:*:*:*

EPSS

Процентиль: 92%
0.07819
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

ubuntu
почти 17 лет назад

Multiple integer overflows in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to execute arbitrary code via an Audible Audio (.aa) file with a large (1) nlen or (2) vlen Tag value, each of which triggers a heap-based buffer overflow.

debian
почти 17 лет назад

Multiple integer overflows in the Audible::Tag::readTag function in me ...

github
больше 3 лет назад

Multiple integer overflows in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to execute arbitrary code via an Audible Audio (.aa) file with a large (1) nlen or (2) vlen Tag value, each of which triggers a heap-based buffer overflow.

EPSS

Процентиль: 92%
0.07819
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-119