PT-2007-6678 · Justsystems · Justsystems Ichitaro+2
Published
2007-10-28
·
Updated
2017-07-29
·
CVE-2007-5687
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
JustSystems Ichitaro versions 2004 through 2007
JustSystems Ichitaro versions 11 through 13
Description
The issue concerns multiple buffer overflows in the rich text processing functionality. These overflows can be triggered by a long
pard field or font name in the fcharset0 field, which is not properly handled in the JSTARO4.OCX component, or by a long title, which is not properly handled by the TJSVDA.DLL component. This can allow remote attackers to execute arbitrary code.Recommendations
For JustSystems Ichitaro versions 2004 through 2007, consider disabling the rich text processing functionality until a patch is available.
For JustSystems Ichitaro versions 11 through 13, restrict access to the
JSTARO4.OCX and TJSVDA.DLL components to minimize the risk of exploitation.
As a temporary workaround, avoid using long pard fields, font names in the fcharset0 field, and long titles in the affected software until the issue is resolved.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jstaro4.Ocx
Justsystems Ichitaro
Tjsvda.Dll