#1040593 kodi: CVE-2023-30207

Package:
src:kodi
Source:
src:kodi
Submitter:
Moritz Mühlenhoff
Date:
2023-07-13 17:36:17 UTC
Severity:
normal
Tags:
#1040593#5
Date:
2023-07-07 18:57:26 UTC
From:
To:
Hi,

The following vulnerability was published for kodi.

CVE-2023-30207[0]:
| A divide by zero issue discovered in Kodi Home Theater Software 19.5
| and earlier allows attackers to cause a denial of service via use of
| crafted mp3 file.

https://github.com/xbmc/xbmc/issues/22378
https://github.com/xbmc/xbmc/pull/22391
https://github.com/xbmc/xbmc/commit/dbc00c500f4c4830049cc040a61c439c580eea73

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2023-30207
https://www.cve.org/CVERecord?id=CVE-2023-30207

Please adjust the affected versions in the BTS as needed.

#1040593#10
Date:
2023-07-07 19:29:26 UTC
From:
To:
Dear Moritz,

Thanks for the report! I fixed it proactively back in 20.0~rc2+dfsg-2 so only oldstable and oldstable-bpo are affected.
I will upload the backport from bookworm to bullseye-bpo soon.