CRITICAL
stakira OpenUtau ZIP Archive VoicebankInstaller.cs VoicebankInstaller path traversal
Published Jan 7, 2023
9.8
CRITICALCVSS 3.1
EPSS 1.06%
Description
A vulnerability was found in stakira OpenUtau. It has been classified as critical. This affects the function VoicebankInstaller of the file OpenUtau.Core/Classic/VoicebankInstaller.cs of the component ZIP Archive Handler. The manipulation leads to path traversal. Upgrading to version 0.0.991 is able to address this issue. The identifier of the patch is 849a0a6912aac8b1c28cc32aa1132a3140caff4a. It is recommended to upgrade the affected component. The identifier VDB-217617 was assigned to this vulnerability.
Affected products
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-52140 Advisory
- https://github.com/stakira/OpenUtau/commit/849a0a6912aac8b1c28cc32aa1132a3140caff4a patch
- https://github.com/stakira/OpenUtau/pull/544 issue-trackingPatch
- https://github.com/stakira/OpenUtau/releases/tag/build%2F0.0.991 patchRelease Notes
- https://vuldb.com/?ctiid.217617 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.217617 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-52140 | Advisory | |
| https://github.com/stakira/OpenUtau/commit/849a0a6912aac8b1c28cc32aa1132a3140caff4a | patch | |
| https://github.com/stakira/OpenUtau/pull/544 | issue-trackingPatch | |
| https://github.com/stakira/OpenUtau/releases/tag/build%2F0.0.991 | patchRelease Notes | |
| https://vuldb.com/?ctiid.217617 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.217617 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jan 7, 2023
Updated Aug 3, 2024
Reserved Jan 7, 2023
Link CVE-2022-4880
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-52140 Assigner VulDB
Published Jan 7, 2023
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2022-52140