v16 Vulnerability to report
#1
Hello,

I have found a minor remote vulnerability in Kodi. Can an official developper or admin contact me back so I can give you all the details to fix it?

Thanks in advance.
Regards,
Guillaume
Reply
#2
Why don't you just post it here so it could be fixed by someone why has time for v17
Regardless there won't be any update for v16 anymore.
Read/follow the forum rules.
For troubleshooting and bug reporting, read this first
Interested in seeing some YouTube videos about Kodi? Go here and subscribe
Reply
#3
I usually never disclose vulnerabilities publicily, instead I privately report it to the developpers, giving a reasonable time for a fix (even for a minor vulnerability).
However I wasn't aware v16 was EOL and would not be fixed. I will thus publish the vulnerability soon and post it here then. If a developper want to take a look at it before I do that, send me a mail/PM.

Regards,
Guillaume
Reply
#4
Kodi embedded web server can be remotely crashed by sending a single GET request containing "../" multiple times.

A working exploit is available at : https://www.exploit-db.com/exploits/40208/

Regards,
Guillaume
Reply
#5
I feel it's been forgotten. Thank you for reporting this gkweb76, there's been some work in the pipeline to protect against path traversal that might resolve this issue but haven't tested to see if it actually does.
The janitor, cleaner of cruft, defender of style. Also known as the unfunny guy that doesn't understand signatures.
Reply

Logout Mark Read Team Forum Stats Members Help
Vulnerability to report0