PT-2017-16806 · Kodi+1 · Chorus2+1

Eric Flokstra

·

Published

2017-02-28

·

Updated

2024-01-23

·

CVE-2017-5982

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Chorus2 version 2.4.2
Description The issue allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by "image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd". This is a directory traversal vulnerability in the Chorus2 add-on for Kodi.
Recommendations For Chorus2 version 2.4.2, consider disabling the add-on until a patch is available to prevent exploitation of the directory traversal vulnerability. Restrict access to sensitive files and directories to minimize the risk of unauthorized access.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1659
CVE-2017-5982
DLA-3712-1

Affected Products

Alt Linux
Chorus2