CVE-2022-4880
Summary
| CVE | CVE-2022-4880 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-07 13:15:00 UTC |
| Updated | 2023-11-07 03:59:00 UTC |
| Description | A vulnerability was found in stakira OpenUtau. It has been classified as critical. This affects the function VoicebankInstaller of the file OpenUtau.Core/Classic/VoicebankInstaller.cs of the component ZIP Archive Handler. The manipulation leads to path traversal. Upgrading to version 0.0.991 is able to address this issue. The identifier of the patch is 849a0a6912aac8b1c28cc32aa1132a3140caff4a. It is recommended to upgrade the affected component. The identifier VDB-217617 was assigned to this vulnerability. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Prevent from zip slip attack / 防范zip上级文件夹攻击 by oxygen-dioxide · Pull Request #544 · stakira/OpenUtau · GitHub | MISC | github.com | |
| Merge pull request #544 from oxygen-dioxide/zipslip · stakira/OpenUtau@849a0a6 · GitHub | MISC | github.com | |
| vuldb.com | MISC | vuldb.com | |
| vuldb.com | MISC | vuldb.com | |
| Release 0.0.991 · stakira/OpenUtau · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.