PT-2006-5135 · Justsystems · Justsystem Formliner+3

Publicado

2006-08-24

·

Atualizado

2017-07-20

·

CVE-2006-4326

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Justsystem Ichitaro versions 9.x through 13.x Justsystem Ichitaro 2004 Justsystem Ichitaro 2005 Justsystem Ichitaro 2006 Justsystem Ichitaro Government 2006 Justsystem Ichitaro for Linux Justsystem FormLiner versions prior to 20060818
Description The issue allows remote attackers to execute arbitrary code via long Unicode strings in a crafted document. It is being actively exploited by malware, such as Trojan.Tarodrop.
Recommendations For Justsystem Ichitaro versions 9.x through 13.x, update to a version outside of the affected range to resolve the issue. For Justsystem Ichitaro 2004, Justsystem Ichitaro 2005, and Justsystem Ichitaro 2006, update to a version outside of the affected range to resolve the issue. For Justsystem Ichitaro Government 2006, update to a version outside of the affected range to resolve the issue. For Justsystem Ichitaro for Linux, update to a version outside of the affected range to resolve the issue. For Justsystem FormLiner versions prior to 20060818, update to version 20060818 or later to resolve the issue.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-4326

Produtos afetados

Justsystem Formliner
Justsystems Ichitaro
Justsystems Ichitaro Government
Justsystem Ichitaro For Linux