Xbmc Foundation · Kodi · CVE-2017-8314
**Name of the Vulnerable Software and Affected Versions**
Kodi versions 17.1 and earlier
**Description**
The issue allows for arbitrary file write on disk via a Zip file used as subtitles, due to a Directory Traversal vulnerability in the Zip Extraction built-in function.
**Recommendations**
For Kodi versions 17.1 and earlier, update to a version that contains a fix for this issue, as using the built-in Zip Extraction function with subtitles from untrusted sources can lead to arbitrary file writes on disk.