Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd.
{
"binaries": [
{
"binary_name": "kodi",
"binary_version": "15.2+dfsg1-3ubuntu1.1"
},
{
"binary_name": "kodi-addons-dev",
"binary_version": "15.2+dfsg1-3ubuntu1.1"
},
{
"binary_name": "kodi-bin",
"binary_version": "15.2+dfsg1-3ubuntu1.1"
},
{
"binary_name": "kodi-data",
"binary_version": "15.2+dfsg1-3ubuntu1.1"
},
{
"binary_name": "kodi-eventclients-common",
"binary_version": "15.2+dfsg1-3ubuntu1.1"
},
{
"binary_name": "kodi-eventclients-dev",
"binary_version": "15.2+dfsg1-3ubuntu1.1"
},
{
"binary_name": "kodi-eventclients-j2me",
"binary_version": "15.2+dfsg1-3ubuntu1.1"
},
{
"binary_name": "kodi-eventclients-kodi-send",
"binary_version": "15.2+dfsg1-3ubuntu1.1"
},
{
"binary_name": "kodi-eventclients-ps3",
"binary_version": "15.2+dfsg1-3ubuntu1.1"
},
{
"binary_name": "kodi-eventclients-wiiremote",
"binary_version": "15.2+dfsg1-3ubuntu1.1"
}
]
}{
"binaries": [
{
"binary_name": "kodi",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "kodi-addons-dev",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "kodi-bin",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "kodi-data",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "kodi-eventclients-common",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "kodi-eventclients-dev",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "kodi-eventclients-kodi-send",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "kodi-eventclients-ps3",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "kodi-eventclients-wiiremote",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "kodi-repository-kodi",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "xbmc",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "xbmc-addons-dev",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "xbmc-bin",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "xbmc-eventclients-common",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "xbmc-eventclients-dev",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "xbmc-eventclients-ps3",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "xbmc-eventclients-wiiremote",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
},
{
"binary_name": "xbmc-eventclients-xbmc-send",
"binary_version": "2:17.6+dfsg1-1ubuntu1"
}
]
}{
"binaries": [
{
"binary_name": "kodi",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-addons-dev",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-addons-dev-common",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-bin",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-data",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-eventclients-common",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-eventclients-dev",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-eventclients-dev-common",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-eventclients-kodi-send",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-eventclients-ps3",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-eventclients-python",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-eventclients-wiiremote",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-eventclients-zeroconf",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-repository-kodi",
"binary_version": "2:19.4+dfsg1-2"
},
{
"binary_name": "kodi-tools-texturepacker",
"binary_version": "2:19.4+dfsg1-2"
}
]
}{
"binaries": [
{
"binary_name": "kodi",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-addons-dev",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-addons-dev-common",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-bin",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-data",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-eventclients-common",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-eventclients-dev",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-eventclients-dev-common",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-eventclients-kodi-send",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-eventclients-ps3",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-eventclients-python",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-eventclients-wiiremote",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-eventclients-zeroconf",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-repository-kodi",
"binary_version": "2:20.5+dfsg-1ubuntu1"
},
{
"binary_name": "kodi-tools-texturepacker",
"binary_version": "2:20.5+dfsg-1ubuntu1"
}
]
}{
"binaries": [
{
"binary_name": "kodi",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-addons-dev",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-addons-dev-common",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-bin",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-data",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-eventclients-common",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-eventclients-dev",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-eventclients-dev-common",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-eventclients-kodi-send",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-eventclients-ps3",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-eventclients-python",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-eventclients-wiiremote",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-eventclients-zeroconf",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-repository-kodi",
"binary_version": "2:21.2+dfsg-1build2"
},
{
"binary_name": "kodi-tools-texturepacker",
"binary_version": "2:21.2+dfsg-1build2"
}
]
}{
"binaries": [
{
"binary_name": "kodi",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-addons-dev",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-addons-dev-common",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-bin",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-data",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-eventclients-common",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-eventclients-dev",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-eventclients-dev-common",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-eventclients-kodi-send",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-eventclients-ps3",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-eventclients-python",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-eventclients-wiiremote",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-eventclients-zeroconf",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-repository-kodi",
"binary_version": "2:21.2+dfsg-4build2"
},
{
"binary_name": "kodi-tools-texturepacker",
"binary_version": "2:21.2+dfsg-4build2"
}
]
}