PT-2006-5135 · Justsystems · Justsystem Formliner+3

Published

2006-08-24

·

Updated

2017-07-20

·

CVE-2006-4326

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Justsystem Ichitaro versions 9.x through 13.x Justsystem Ichitaro 2004 Justsystem Ichitaro 2005 Justsystem Ichitaro 2006 Justsystem Ichitaro Government 2006 Justsystem Ichitaro for Linux Justsystem FormLiner versions prior to 20060818
Description The issue allows remote attackers to execute arbitrary code via long Unicode strings in a crafted document. It is being actively exploited by malware, such as Trojan.Tarodrop.
Recommendations For Justsystem Ichitaro versions 9.x through 13.x, update to a version outside of the affected range to resolve the issue. For Justsystem Ichitaro 2004, Justsystem Ichitaro 2005, and Justsystem Ichitaro 2006, update to a version outside of the affected range to resolve the issue. For Justsystem Ichitaro Government 2006, update to a version outside of the affected range to resolve the issue. For Justsystem Ichitaro for Linux, update to a version outside of the affected range to resolve the issue. For Justsystem FormLiner versions prior to 20060818, update to version 20060818 or later to resolve the issue.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-4326

Affected Products

Justsystem Formliner
Justsystems Ichitaro
Justsystems Ichitaro Government
Justsystem Ichitaro For Linux