Path traversal vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product installs a crafted UTAU voicebank installer (.uar file, .zip file) to UTAU, an arbitrary file may be placed.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://jvn.jp/en/jp/JVN71404925/ |
|
| https://utau2008.xrea.jp/ |
|
History
Tue, 29 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-10-29T14:51:18.432Z
Reserved: 2024-05-22T05:26:03.269Z
Link: CVE-2024-32944
Updated: 2024-08-02T02:27:52.399Z
Status : Deferred
Published: 2024-05-28T03:15:08.563
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-32944
No data.
OpenCVE Enrichment
No data.
Weaknesses