Multiple vulnerabilities have been found in Kodi, the worst of which could allow remote attackers to execute arbitrary code.
|Package||media-tv/kodi on all architectures|
|Affected versions||< 17.2|
|Unaffected versions||>= 17.2|
Kodi (formerly XBMC) is a free and open-source media player software application.
Multiple vulnerabilities have been discovered in Kodi. Please review the CVE identifiers referenced below for details.
A remote attacker could entice a user to open a specially crafted image file using Kodi, possibly resulting in a Denial of Service condition.
Furthermore, a remote attacker could entice a user process a specially crafted ZIP file containing subtitles using Kodi, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition.
There is no known workaround at this time.
All Kodi users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=media-tv/kodi-17.2"