CVE-2020-13152: Kde Amarok

Medium severity, CVSS 5.5. EPSS: 3.5% chance of exploitation in the next 30 days.

A remote user can create a specially crafted M3U file, media playlist file that when loaded by the target user, will trigger a memory leak, whereby Amarok 2.8.0 continue to waste resources over time, eventually allows attackers to cause a denial of service.

Affected products

  • Kde Amarok: version 2.8.0 only

Published 2020-05-20. Last modified 2026-06-17.