Summary
The remote host is missing an update to amarok
announced via advisory USN-739-1.
Solution
The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 7.10:
amarok 2:1.4.7-0ubuntu3.2
Ubuntu 8.04 LTS:
amarok 2:1.4.9.1-0ubuntu3.2
Ubuntu 8.10:
amarok 2:1.4.10-0ubuntu3.1
In general, a standard system upgrade is sufficient to effect the necessary changes.
https://secure1.securityspace.com/smysecure/catid.html?in=USN-739-1
Insight
It was discovered that Amarok did not correctly handle certain malformed tags in Audible Audio (.aa) files. If a user were tricked into opening a crafted Audible Audio file, an attacker could execute arbitrary code with the privileges of the user invoking the program.
Severity
Classification
-
CVE CVE-2004-2761, CVE-2008-4564, CVE-2009-0135, CVE-2009-0136, CVE-2009-0538 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities