PT-2022-27633 · Unknown · Ubi Reader

·

CVE-2022-4572

·

Published

2022-12-17

·

Updated

2022-12-22

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions UBI Reader versions up to 0.8.0
Description A vulnerability has been found in the UBIFS File Handler component, specifically affecting the ubireader extract files function of the file ubireader/ubifs/output.py. This issue leads to path traversal and can be exploited remotely.
Recommendations For UBI Reader versions up to 0.8.0, upgrade to version 0.8.5 to address this issue. As a temporary workaround, consider restricting access to the ubireader extract files function until the upgrade is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4572
GHSA-HC37-84V3-8GMQ
PYSEC-2022-43016

Affected Products

Ubi Reader