Bug#855225: kodi: CVE-2017-5982: Unrestricted file download

2020-11-13 Thread Tobias Frost
Control: forwarded -1 https://github.com/xbmc/xbmc/pull/14501 Control: fixed -1 2:18.5+dfsg1-1~exp0 ^^ fixed upstream with this pull request ^^ d/changelog misses the CVE entry, therefore not closing this bug.

Bug#855225: kodi: CVE-2017-5982: Unrestricted file download

2017-04-29 Thread Antoine Beaupré
On 2017-04-28 19:07:06, Bálint Réczey wrote: [...] > I have forwarded this info to upstream bug tracker but I have no high hopes in > getting the issue solved. > > I plan blogging about Kodi 17.1 being in both Stretch and Zesty and mention > this issue as a reason for people to not trust any inst

Bug#855225: kodi: CVE-2017-5982: Unrestricted file download

2017-04-28 Thread Bálint Réczey
Hi Antoine, Thanks for the detailed analysis! 2017-04-26 19:05 GMT+02:00 Antoine Beaupre : > affects 85225 xbmc > package xbmc > found 85225 2:11.0~git20120510.82388d5-1 > thanks > > I can confirm this affects both jessie-backports and wheezy. I've been > able to access random files on my Kodi i

Bug#855225: kodi: CVE-2017-5982: Unrestricted file download

2017-04-26 Thread Antoine Beaupre
affects 85225 xbmc package xbmc found 85225 2:11.0~git20120510.82388d5-1 thanks I can confirm this affects both jessie-backports and wheezy. I've been able to access random files on my Kodi install using: http://localhost:8080/image/image%3A%2F%2F%2e%2e%252f%2e%2e%252f%2e%2e%252f%2e%2e%252fetc%25

Bug#855225: kodi: CVE-2017-5982: Unrestricted file download

2017-02-15 Thread Bálint Réczey
Control: tags -1 confirmed Control: found -1 15.1+dfsg1-1 2017-02-15 19:03 GMT+01:00 Salvatore Bonaccorso : > Source: kodi > Severity: important > Tags: upstream security > Forwarded: http://trac.kodi.tv/ticket/17314 > > Hi, > > the following vulnerability was published for kodi. I did not had th

Bug#855225: kodi: CVE-2017-5982: Unrestricted file download

2017-02-15 Thread Salvatore Bonaccorso
Source: kodi Severity: important Tags: upstream security Forwarded: http://trac.kodi.tv/ticket/17314 Hi, the following vulnerability was published for kodi. I did not had the time to verify if 17.0 is affected. Could you please check and add according found versions to this bug please or otherwis