PT-2024-24991 · Utau · Utau

·

CVE-2024-32944

·

Published

2024-05-28

·

Updated

2024-10-29

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions UTAU versions prior to v0.4.19
Description A path traversal issue exists, allowing an arbitrary file to be placed if a user installs a crafted UTAU voicebank installer, such as a .uar or .zip file, to UTAU.
Recommendations For versions prior to v0.4.19, update to version v0.4.19 or later to resolve the issue. As a temporary workaround, consider avoiding the installation of untrusted UTAU voicebank installers until the issue is resolved.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-32944

Affected Products

Utau