PDA

View Full Version : Kodi v17.2 & V17.3 Released :A minor bug fix & security issue



Kimbo
05-24-2017, 11:39 AM
C/P Kodi

We're happy to present you this small bugfix release for the v17 “Krypton” range which contains our continuous effort to further improve the v17 range. This release consist of several fixes on top of the v17 and v17.1 release to further improve stability and usablity. Additionally this also inclused a security patch regarding subtitle zip files. We sure would like to thank every one involved with either development, testing or simply helping out others with answering their questions.

Fixes done in this release:



Fix selection after channelgroup switching in PVR guide window
Fix handling of gaps that caused eradic behaviour in EPG grid
Allow backing out of fullscreen pictures by mapping longpress guesture
Quick fix for wake up command not being called in PVR power management
Use alternative method to check if platform updates have been installed on Windows
Set the minimum version in the code which is currently OSX 10.8
Fix possible security flaw which could abused .zip files which try to traverse to a parent directory
Use the correct ttc font from the video file for subtitles on Windows
Detect and delete zero-byte database files which causes crashes




Security

You may have read in the news that malicious subtitle zip files could potentionally infect and harm your media player including Kodi. When Check Point researchers uncovered this flaw they contact us up front to less us know about this flaw. Our developers fixed this secuity gap and have added the fix to this v17.2 release. As such we highly encourage all users to install this latest version! Any previous Kodi version will not get any security patch. We have began the roll out of this version and Android Play Store as well as Windows Store have this update pending and will roll out as soon as possible. Please be patient if you are using these store versions. Our official download page of course has the regular install files available for the supported platforms.

What else is new?

In the bugfix releases we never include any new features. They are as feature complete as the initial version with the diference is they contain stability and usability fixes. If you are curious you can read up on all the v17 changes here: Kodi v17.0 “Krypton”

V17.3

Fixes:



Fixed missing binary add-ons on release time
Fixed crash on older distros like Ubuntu 14.04 with GCC 4.8 compiler

crazed 9.6
05-24-2017, 05:29 PM
nice to see that Kodi was quick to fix this subtite exploit :)
thnx for the news Laser


http://thehackernews.com/2017/05/movie-subtitles-malware.html

limes
05-24-2017, 06:11 PM
hope you don't mind me adding a link for update..np...:)

Kimbo
05-24-2017, 06:21 PM
Thank you limes for the input but it leads to another forum, If you use Crazed's link it better explains.

FCSI
05-24-2017, 11:03 PM
Nice review Laser i saw the update in the play store but i didn't update it yet . Thanks

dara
05-25-2017, 12:04 AM
17.3 rolled out immediately. Must be a serious flaw.

Kimbo
05-25-2017, 12:18 PM
Added 17.3 info in post #1

leafs99
05-28-2017, 01:32 AM
Do we have to worry about this security risk in some of the boxes like avov that need to be rooted before we can install other things within the box? I only see version 16.2 in that box and is this security risk valid for the avov box?

dara
05-28-2017, 02:37 AM
The security risk is specifically from subtitle files. So, if you avoid those, you won't have an issue.

leafs99
05-28-2017, 11:49 PM
Dara, thanks again for your professional experience. It makes more sense to me now..I have never downloaded any third party subtitle services. Thank you.

Marley
05-31-2017, 09:37 PM
any boxes put out new update

leafs99
06-11-2017, 09:32 PM
Yep..Looks like almost all of them have it in the market now but only some boxes will be able to install it unless we have the capability to install a newer version of android OS on the older boxes..vixo 2 and tvonline +..