CVE-2017-5982: Path Traversal
Published Feb 28, 2017
·Updated
Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd.
Affected Software
1 affected component
Kodi Kodi=17.1
Event History
Feb 28, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5982?
CVE-2017-5982 has a high severity rating of 7.5 according to the CVSS v3.0.
2
How do I fix CVE-2017-5982?
To fix CVE-2017-5982, update the Chorus2 add-on for Kodi to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2017-5982?
CVE-2017-5982 is a directory traversal vulnerability that allows unauthorized access to file system paths.
4
What could happen if CVE-2017-5982 is exploited?
If exploited, CVE-2017-5982 allows remote attackers to read sensitive files on the server, such as the /etc/passwd file.
5
Which software is affected by CVE-2017-5982?
CVE-2017-5982 affects the Chorus2 2.4.2 add-on for the Kodi media player.