Description
Buffer overflow vulnerability in Kodi xbmc up to 19.0, allows attackers to cause a denial of service due to improper length of values passed to istream.
References (5)
Core 5
Core References
Patch, Third Party Advisory
https://github.com/fuzzard/xbmc/commit/80c8138c09598e88b4ddb6dbb279fa193bbb3237
Patch, Third Party Advisory
https://github.com/xbmc/xbmc/commit/48730b64494798705d46dfccc4029bd36d072df3
Exploit, Issue Tracking, Third Party Advisory
https://github.com/xbmc/xbmc/issues/20305
Patch, Third Party Advisory
https://github.com/xbmc/xbmc/pull/20306
Mailing List mailing-list
https://lists.debian.org/debian-lts-announce/2024/01/msg00009.html
Scores
CVSS v3
5.5
EPSS
0.0027
EPSS Percentile
50.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-120
Status
published
Products (1)
kodi/kodi
< 19.0
Published
Nov 01, 2021
Tracked Since
Feb 18, 2026