PT-2017-15538 · Justsystems · Justsystems Ichitaro Office

Publicado

2017-02-24

·

Atualizado

2022-04-19

·

CVE-2017-2790

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions JustSystems Ichitaro Office (affected versions not specified)
Description The issue occurs when processing a specific record type from an Excel file, leading to a heap-based buffer overflow. This can result in code execution under the context of the application. The overflow happens because the application trusts that the size is greater than zero, subtracts one from the length, and uses this result as the size for a memcpy.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-2790

Produtos afetados

Justsystems Ichitaro Office