[Bug 318555] Re: Amarok - integer overflows and unchecked allocation vulnerabilities

Launchpad Bug Tracker 318555 at bugs.launchpad.net
Tue Mar 17 16:46:40 UTC 2009


This bug was fixed in the package amarok - 2:1.4.10-0ubuntu3.1

---------------
amarok (2:1.4.10-0ubuntu3.1) intrepid-security; urgency=low

  * SECURITY UPDATE: integer overflows allow remote attackers to execute
    arbitrary code via an Audible Audio (.aa) file (LP: #318555)
    - debian/patches/security_audible_tags.diff fix integer overflow while
      reading audible aa file tags. Based on upstream patch.
    - http://websvn.kde.org/?view=rev&revision=908415
    - http://www.trapkit.de/advisories/TKADV2009-002.txt
    - CVE-2009-0135
    - CVE-2009-0136

 -- Harald Sitter <apachelogger at ubuntu.com>   Mon, 19 Jan 2009 22:05:24
+0100

-- 
Amarok - integer overflows and unchecked allocation vulnerabilities
https://bugs.launchpad.net/bugs/318555
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to amarok in ubuntu.




More information about the kubuntu-bugs mailing list