PT-2024-24991 · Utau · Utau

Yu Ishibashi

·

Published

2024-05-28

·

Updated

2024-10-29

·

CVE-2024-32944

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions UTAU versions prior to v0.4.19
Description A path traversal issue exists, allowing an arbitrary file to be placed if a user installs a crafted UTAU voicebank installer, such as a .uar or .zip file, to UTAU.
Recommendations For versions prior to v0.4.19, update to version v0.4.19 or later to resolve the issue. As a temporary workaround, consider avoiding the installation of untrusted UTAU voicebank installers until the issue is resolved.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-32944

Affected Products

Utau