Bug 479946

Summary: amarok: integer overflows and unchecked allocation when parsing malformed Audible digital audio files
Product: [Other] Security Response Reporter: Jan Lieskovsky <jlieskov>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED DUPLICATE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: gauret
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://www.trapkit.de/advisories/TKADV2009-002.txt
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-01-14 08:59:29 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Diff for audibletag.cpp file between latest F10 amarok version (2.0-2.fc10) and latest upstream amarok (2.0.1.1) none

Description Jan Lieskovsky 2009-01-14 08:52:14 UTC
Multiple integer overflow flaws (leading to heap-based buffer overflows) and
unchecked allocation vulnerabilities has been reported in the Amarok multimedia
player, when parsing malformed Audible digital audio files. A remote attacker
could use this flaw to execute arbitrary code in the context of user running
the Amarok multimedia player.

References:
http://www.trapkit.de/advisories/TKADV2009-002.txt
http://bugs.gentoo.org/show_bug.cgi?id=254896
http://amarok.kde.org/en/releases/2.0.1.1

Proposed solution:
Please upgrade to upstream version of 2.0.1.1.

Comment 1 Jan Lieskovsky 2009-01-14 08:53:16 UTC
This issue affects all versions of the Amarok multimedia player package,
as shipped with Fedora releases of 9, 10 and devel.

Please update to upstream version 2.0.1.1.

Comment 2 Jan Lieskovsky 2009-01-14 08:56:52 UTC
Created attachment 328959 [details]
Diff for audibletag.cpp file between latest F10 amarok version (2.0-2.fc10) and latest upstream amarok (2.0.1.1)

Comment 3 Tomas Hoger 2009-01-14 08:59:29 UTC

*** This bug has been marked as a duplicate of bug 479560 ***