VYPR
Vendor

Ubi Reader Project

Products
1
CVEs
2
Across products
2
Status
Private

Products

1

Recent CVEs

2
  • CVE-2023-0591MedJan 31, 2023
    risk 0.29cvss 5.5epss 0.00

    ubireader_extract_files is vulnerable to path traversal when run against specifically crafted UBIFS files, allowing the attacker to overwrite files outside of the extraction directory (provided the process has write access to that file or directory). This is due to the fact…

  • CVE-2022-4572MedDec 17, 2022
    risk 0.28cvss 5.4epss 0.01

    A vulnerability, which was classified as problematic, has been found in UBI Reader up to 0.8.0. Affected by this issue is the function ubireader_extract_files of the file ubireader/ubifs/output.py of the component UBIFS File Handler. The manipulation leads to path traversal. The…