PT-2006-5135 · Justsystems · Justsystem Formliner+3
Publicado
2006-08-24
·
Atualizado
2017-07-20
·
CVE-2006-4326
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Justsystem Ichitaro versions 9.x through 13.x
Justsystem Ichitaro 2004
Justsystem Ichitaro 2005
Justsystem Ichitaro 2006
Justsystem Ichitaro Government 2006
Justsystem Ichitaro for Linux
Justsystem FormLiner versions prior to 20060818
Description
The issue allows remote attackers to execute arbitrary code via long Unicode strings in a crafted document. It is being actively exploited by malware, such as Trojan.Tarodrop.
Recommendations
For Justsystem Ichitaro versions 9.x through 13.x, update to a version outside of the affected range to resolve the issue.
For Justsystem Ichitaro 2004, Justsystem Ichitaro 2005, and Justsystem Ichitaro 2006, update to a version outside of the affected range to resolve the issue.
For Justsystem Ichitaro Government 2006, update to a version outside of the affected range to resolve the issue.
For Justsystem Ichitaro for Linux, update to a version outside of the affected range to resolve the issue.
For Justsystem FormLiner versions prior to 20060818, update to version 20060818 or later to resolve the issue.
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Justsystem Formliner
Justsystems Ichitaro
Justsystems Ichitaro Government
Justsystem Ichitaro For Linux