Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd.
{
"binaries": [
{
"binary_version": "15.2+dfsg1-3ubuntu1.1",
"binary_name": "kodi"
},
{
"binary_version": "15.2+dfsg1-3ubuntu1.1",
"binary_name": "kodi-addons-dev"
},
{
"binary_version": "15.2+dfsg1-3ubuntu1.1",
"binary_name": "kodi-bin"
},
{
"binary_version": "15.2+dfsg1-3ubuntu1.1",
"binary_name": "kodi-data"
},
{
"binary_version": "15.2+dfsg1-3ubuntu1.1",
"binary_name": "kodi-eventclients-common"
},
{
"binary_version": "15.2+dfsg1-3ubuntu1.1",
"binary_name": "kodi-eventclients-dev"
},
{
"binary_version": "15.2+dfsg1-3ubuntu1.1",
"binary_name": "kodi-eventclients-j2me"
},
{
"binary_version": "15.2+dfsg1-3ubuntu1.1",
"binary_name": "kodi-eventclients-kodi-send"
},
{
"binary_version": "15.2+dfsg1-3ubuntu1.1",
"binary_name": "kodi-eventclients-ps3"
},
{
"binary_version": "15.2+dfsg1-3ubuntu1.1",
"binary_name": "kodi-eventclients-wiiremote"
}
]
}
{
"binaries": [
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "kodi"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "kodi-addons-dev"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "kodi-bin"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "kodi-data"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "kodi-eventclients-common"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "kodi-eventclients-dev"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "kodi-eventclients-kodi-send"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "kodi-eventclients-ps3"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "kodi-eventclients-wiiremote"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "kodi-repository-kodi"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "xbmc"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "xbmc-addons-dev"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "xbmc-bin"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "xbmc-eventclients-common"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "xbmc-eventclients-dev"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "xbmc-eventclients-ps3"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "xbmc-eventclients-wiiremote"
},
{
"binary_version": "2:17.6+dfsg1-1ubuntu1",
"binary_name": "xbmc-eventclients-xbmc-send"
}
]
}
{
"binaries": [
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-addons-dev"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-addons-dev-common"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-bin"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-data"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-eventclients-common"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-eventclients-dev"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-eventclients-dev-common"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-eventclients-kodi-send"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-eventclients-ps3"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-eventclients-python"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-eventclients-wiiremote"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-eventclients-zeroconf"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-repository-kodi"
},
{
"binary_version": "2:19.4+dfsg1-2",
"binary_name": "kodi-tools-texturepacker"
}
]
}
{
"binaries": [
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-addons-dev"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-addons-dev-common"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-bin"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-data"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-eventclients-common"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-eventclients-dev"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-eventclients-dev-common"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-eventclients-kodi-send"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-eventclients-ps3"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-eventclients-python"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-eventclients-wiiremote"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-eventclients-zeroconf"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-repository-kodi"
},
{
"binary_version": "2:20.5+dfsg-1ubuntu1",
"binary_name": "kodi-tools-texturepacker"
}
]
}
{
"binaries": [
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-addons-dev"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-addons-dev-common"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-bin"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-data"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-eventclients-common"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-eventclients-dev"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-eventclients-dev-common"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-eventclients-kodi-send"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-eventclients-ps3"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-eventclients-python"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-eventclients-wiiremote"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-eventclients-zeroconf"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-repository-kodi"
},
{
"binary_version": "2:21.2+dfsg-4build2",
"binary_name": "kodi-tools-texturepacker"
}
]
}