CVE-2020-13152
NixOS vulnerability analysis and mitigation

Overview

CVE-2020-13152 affects Amarok 2.8.0, a media player application. The vulnerability allows remote attackers to cause a denial of service condition through a specially crafted M3U playlist file that triggers a memory leak. When loaded by the target user, the application continues to waste resources over time, eventually consuming all available system resources (NVD, Debian Tracker).

Technical details

The vulnerability is classified as a memory leak issue (CWE-401: Missing Release of Memory after Effective Lifetime). It has a CVSS v3.1 base score of 5.5 (Medium) with vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H, and a CVSS v2.0 score of 4.3 (NVD). The issue occurs when processing maliciously crafted M3U playlist files, causing the application to continuously consume system resources without proper release.

Impact

When exploited, the vulnerability results in a denial of service condition where Amarok continues to waste system resources over time. This can lead to degraded system performance and potentially render the application unusable (NVD, R00t Exploit).

Exploitability

The vulnerability requires user interaction to open a maliciously crafted M3U file. Proof-of-concept exploits have been publicly demonstrated, showing how the vulnerability can be triggered using specially crafted M3U files that cause the application to consume excessive CPU resources and eventually crash (R00t Exploit, Packet Storm).

Mitigation and workarounds

The vulnerability affects Amarok version 2.8.0. Users should upgrade to a patched version when available. In Debian systems, the issue is considered unimportant from a security perspective as it only affects client application resource usage (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management