PT-2006-5135 · Justsystems · Justsystem Formliner+3
Published
2006-08-24
·
Updated
2017-07-20
·
CVE-2006-4326
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Justsystem Ichitaro versions 9.x through 13.x
Justsystem Ichitaro 2004
Justsystem Ichitaro 2005
Justsystem Ichitaro 2006
Justsystem Ichitaro Government 2006
Justsystem Ichitaro for Linux
Justsystem FormLiner versions prior to 20060818
Description
The issue allows remote attackers to execute arbitrary code via long Unicode strings in a crafted document. It is being actively exploited by malware, such as Trojan.Tarodrop.
Recommendations
For Justsystem Ichitaro versions 9.x through 13.x, update to a version outside of the affected range to resolve the issue.
For Justsystem Ichitaro 2004, Justsystem Ichitaro 2005, and Justsystem Ichitaro 2006, update to a version outside of the affected range to resolve the issue.
For Justsystem Ichitaro Government 2006, update to a version outside of the affected range to resolve the issue.
For Justsystem Ichitaro for Linux, update to a version outside of the affected range to resolve the issue.
For Justsystem FormLiner versions prior to 20060818, update to version 20060818 or later to resolve the issue.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Justsystem Formliner
Justsystems Ichitaro
Justsystems Ichitaro Government
Justsystem Ichitaro For Linux