Package: kodi Version: 2:17.6+dfsg1-4+deb10u1 CVE IDs: - CVE-2017-5982: Directory traversal vulnerability allowing remote attackers to read arbitrary files via encoded dot dot slash in the image path. - CVE-2021-42917: Buffer overflow vulnerability causing denial of service due to improper length of values passed to istream. - CVE-2023-23082: Heap buffer overflow vulnerability causing denial of service due to improper length of the value passed to the offset argument. - CVE-2023-30207: Divide by zero issue causing denial of service via crafted mp3 file. Affected Version: 2:17.6+dfsg1-4+deb10u1 Fixed Version: Same version was fixed for Debian 10 Buster. Recommendation: Upgrade kodi packages. Tracking: Detailed security status available at: https://security-tracker.debian.org/tracker/kodi Advisory Source: Debian LTS Security Advisory DLA-3712-1, from debian-lts@lists.debian.org, dated January 17, 2024. Additional Info: Further information on Debian LTS and update application is available at: https://wiki.debian.org/LTS