A heap buffer overflow vulnerability in Kodi Home Theater Software up to 19.5 allows attackers to cause a denial of service due to an improper length of the value passed to the offset argument.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/xbmc/xbmc/issues/22377 | issue tracking patch exploit third party advisory |
https://github.com/xbmc/xbmc/commit/8c2aafb6d4987833803e037c923aaf83f9ff41e1 | third party advisory patch |
https://github.com/xbmc/xbmc/pull/22380 | third party advisory patch |
https://github.com/xbmc/xbmc/pull/22380/commits/00fec1dbdd1df827872c7b55ad93059636dfc076 | |
https://github.com/xbmc/xbmc/pull/22380/commits/7e5f9fbf9aaa3540aab35e7504036855b23dcf60 | |
https://lists.debian.org/debian-lts-announce/2024/01/msg00009.html | mailing list |