{"id":930,"date":"2017-05-24T23:00:00","date_gmt":"2017-05-24T22:00:00","guid":{"rendered":"https:\/\/droix.co.uk\/blogs\/kodi-subtitles-bug-vlc-code-security-concerns\/"},"modified":"2017-05-24T23:00:00","modified_gmt":"2017-05-24T22:00:00","slug":"kodi-subtitles-bug-vlc-code-security-concerns","status":"publish","type":"post","link":"https:\/\/droix.net\/blogs\/ar\/kodi-subtitles-bug-vlc-code-security-concerns\/","title":{"rendered":"Kodi Subtitles Bug VLC Code Security Concerns"},"content":{"rendered":"\n<p>If you have seen a notification about an update for Kodi to fix security concerns, or use subtitles when in Kodi or a similar application, this post details the changes you may make to need to ensure your mini home theatre PC or other gadget is secure.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p>Kodi 17.3 has been released today in quick succession to 17.2<\/p>\n\n\n\n<p>Although 17.2 addressed the concerns raised over security, it still introduced some&nbsp;minor bugs, 17.3 addresses there:<br><code>Fixed missing binary add-ons on release time<br>\nFixed crash on older distros like Ubuntu 14.04 with GCC 4.8 compiler<\/code><\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/droix.net\/blogs\/wp-content\/uploads\/2021\/09\/240px-Gnome_Subtitles_Icon.svg1_.png\"><img decoding=\"async\" src=\"https:\/\/droix.net\/blogs\/wp-content\/uploads\/2021\/09\/240px-Gnome_Subtitles_Icon.svg1_.png\" alt=\"\" class=\"wp-image-3402\"\/><\/a><\/figure>\n\n\n\n<p>Some code within VLC (some of which is used within Kodi) has been found to not be properly sandboxed. If a malformed (maliciously) subtitle is loaded up, the attacker could theoretically gain access to other areas of your Android device.<\/p>\n\n\n\n<p>In its self, by no means the worst&nbsp;news we have in this world right now, but an insecure device on your network could be a staging point for other, more sensitive devices in your home.<\/p>\n\n\n\n<p>If you never use subtitles when watching video streams (nor see them appear automatically most of the time), there is not a pressing need to update immediately.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><img decoding=\"async\" src=\"https:\/\/droix.net\/blogs\/wp-content\/uploads\/2021\/09\/Kodi17KryptonSplashScreen-300x169.png\" alt=\"Kodi 17 Krypton Splash Screen\" class=\"wp-image-3093\"\/><\/figure><\/div>\n\n\n\n<h5 class=\"wp-block-heading\">Kodi 17 (Krypton)<\/h5>\n\n\n\n<p>If you currently use subtitles in version 17.0 or 17.1 either disable them entirely or at least disable automatic download. To do this, click the Settings icon of a cog in Kodi&#8217;s homescreen, then click on the Player entry. Now select the Language area, &#8220;Auto download first subtitle&#8221; should not be enabled.<\/p>\n\n\n\n<p>To contine to use subtitles, you can update to Kodi 17.3 via <span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"https:\/\/droix.zendesk.com\/hc\/en-gb\/articles\/360010555258-First-Run-Of-Google-s-Play-Store\" target=\"_blank\" rel=\"noopener noreferrer\">Google&#8217;s Play Store<\/a><\/span> or directly via an APK file from https:\/\/www.apkmirror.com\/apk\/xbmc-foundation\/kodi\/kodi-17-3-release\/.<br>If either approach does not allow the update to occur, return to the Play Store and click the Uninstall button. Once this completes, press the Install button.<\/p>\n\n\n\n<p>You can check which version of Kodi Krypton you are currently running by clicking the System shortcut (an icon of a cog) in Kodi&#8217;s homescreen, then click the System Information entry.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><img decoding=\"async\" src=\"https:\/\/droix.net\/blogs\/wp-content\/uploads\/2021\/09\/blog-post-image-4.png\" alt=\"DBMC Logo 128 128\" class=\"wp-image-3153\"\/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><img decoding=\"async\" src=\"https:\/\/droix.net\/blogs\/wp-content\/uploads\/2021\/09\/SplashKodi16-600x3361-150x150-1.png\" alt=\"Kodi 16 Jarvis Splash\" class=\"wp-image-3347\"\/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><img decoding=\"async\" src=\"https:\/\/droix.net\/blogs\/wp-content\/uploads\/2021\/09\/spmc-splash-screen-logo-header1-150x150.jpg\" alt=\"SPMC Splash Screen\" class=\"wp-image-3348\"\/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><img decoding=\"async\" src=\"https:\/\/droix.net\/blogs\/wp-content\/uploads\/2021\/09\/blog-post-image-6-150x150.jpg\" alt=\"LibreELEC Square Logo\" class=\"wp-image-2581\"\/><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><img decoding=\"async\" src=\"https:\/\/droix.net\/blogs\/wp-content\/uploads\/2021\/09\/Openelec_logo_transp_270x1351.png\" alt=\"OpenELEC\" class=\"wp-image-2356\"\/><\/figure><\/div>\n\n\n\n<h5 class=\"wp-block-heading\">&nbsp;<\/h5>\n\n\n\n<h5 class=\"wp-block-heading\">&nbsp;<\/h5>\n\n\n\n<h5 class=\"wp-block-heading\">Kodi Jarvis (16) or earlier in Android, or DBMC (DroiX Media Centre), SPMC , Kodi in LibreELEC 7 or 8, OpenELEC 6<\/h5>\n\n\n\n<p>If you use subtitles disable the them&nbsp;for now. Check with the application author for an available update that came out in late May at the earliest.<br>If you run Kodi 16.1 or earlier in Android, check the <span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"https:\/\/droix.zendesk.com\/hc\/en-gb\/articles\/360010555258-First-Run-Of-Google-s-Play-Store\" target=\"_blank\" rel=\"noopener noreferrer\">Play Store<\/a><\/span> for updates. If your device has Android 4 (KitKat), please see&nbsp;<span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" title=\"Get Kodi 17 (Krypton) On Android 4 Devices!\" href=\"https:\/\/droix.net\/blogs\/wordpress\/get-kodi-17-krypton-on-android-4-jellybean-devices\/\">Get Kodi 17 (Krypton) On Android 4 Devices!<\/a><\/span>&nbsp;for details about Kodi 17 alternatives (as Krypton\/17 requires Android 5 or higher).<br>Check in the threads linked to for updates for FTMC and Mygica that fix the subtitle security issue.<br>DBMC users will need to switch to Kodi or the applications mentioned in the previous link if they need to use subtitles. Once SPMC is updated, we hope to be able to bring out an updated DroiX Media Centre as well. If you are happy to continue to use DBMC without subtitles, please click the System menu, then Add-ons, from here, My Add-ons or Installed Add-ons, then Subtitles. Long click on the installed services, select Info and then click Uninstall for each.<br>OpenELEC and LibreELEC 7 users can either switch to Android or disable subtitles (System, Add-ons, My Add-ons or Installed Add-ons, Subtitles, Long click on the installed services, select Info and then click Uninstall.)<br>If compatible updates are released for either operating system we will post the news here at this blog.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><a href=\"https:\/\/droix.net\/blogs\/wp-content\/uploads\/2021\/09\/banner.png\"><img decoding=\"async\" src=\"https:\/\/droix.net\/blogs\/wp-content\/uploads\/2021\/09\/banner-150x150.png\" alt=\"FTMC Media Center\" class=\"wp-image-3283\"\/><\/a><\/figure><\/div>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"alignright\"><a href=\"https:\/\/droix.net\/blogs\/wp-content\/uploads\/2021\/09\/splash-1.jpg\"><img decoding=\"async\" src=\"https:\/\/droix.net\/blogs\/wp-content\/uploads\/2021\/09\/splash-1-150x150.jpg\" alt=\"Mygica Media Center Splash\" class=\"wp-image-3288\"\/><\/a><\/figure><\/div>\n\n\n\n<h5 class=\"wp-block-heading\">SPMC, FTMC, Mygica<\/h5>\n\n\n\n<p>Check for any FTMC and Mygica updates &nbsp;in the threads linked <span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"https:\/\/droix.net\/blogs\/wordpress\/get-kodi-17-krypton-on-android-4-jellybean-devices\/\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a><\/span>, that fix the subtitle security issue.<\/p>\n\n\n\n<p>To get the latest news about Kodi releases, be sure to keep an eye on&nbsp;<span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"https:\/\/kodi.tv\/blog\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/kodi.tv\/blog<\/a>&nbsp;<\/span>, as well as this blog and with the community at the <span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"https:\/\/DroiDBOXForums.com\" target=\"_blank\" rel=\"noopener noreferrer\">DroiX forum<\/a><\/span>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you have seen a notification about an update for Kodi to fix security concerns, or use subtitles when in Kodi or a similar application, this post details the changes you may make to need to ensure your mini home theatre PC or other gadget is secure.<\/p>\n","protected":false},"author":2,"featured_media":931,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[16,17],"class_list":{"0":"post-930","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"tag-android-tv-box","9":"tag-kodi"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/droix.net\/blogs\/ar\/wp-json\/wp\/v2\/posts\/930","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/droix.net\/blogs\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/droix.net\/blogs\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/droix.net\/blogs\/ar\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/droix.net\/blogs\/ar\/wp-json\/wp\/v2\/comments?post=930"}],"version-history":[{"count":0,"href":"https:\/\/droix.net\/blogs\/ar\/wp-json\/wp\/v2\/posts\/930\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/droix.net\/blogs\/ar\/wp-json\/wp\/v2\/media\/931"}],"wp:attachment":[{"href":"https:\/\/droix.net\/blogs\/ar\/wp-json\/wp\/v2\/media?parent=930"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/droix.net\/blogs\/ar\/wp-json\/wp\/v2\/categories?post=930"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/droix.net\/blogs\/ar\/wp-json\/wp\/v2\/tags?post=930"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}