VYPR

Software Actualizer

by Chewkeanho

Source repositories

CVEs (2)

  • CVE-2026-85649HigSep 4, 2026
    risk 0.44cvss 7.9epss 0.00

    (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate yescrypt password hashes but does not…

  • CVE-2025-47276HigMay 13, 2025
    risk 0.42cvss 7.5epss 0.00

    Actualizer is a single shell script solution to allow developers and embedded engineers to create Debian operating systems (OS). Prior to version 1.2.0, Actualizer uses OpenSSL's "-passwd" function, which uses SHA512 instead of a more suitable password hasher like…