PT-2007-6678 · Justsystems · Justsystems Ichitaro+2

Published

2007-10-28

·

Updated

2017-07-29

·

CVE-2007-5687

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions JustSystems Ichitaro versions 2004 through 2007 JustSystems Ichitaro versions 11 through 13
Description The issue concerns multiple buffer overflows in the rich text processing functionality. These overflows can be triggered by a long pard field or font name in the fcharset0 field, which is not properly handled in the JSTARO4.OCX component, or by a long title, which is not properly handled by the TJSVDA.DLL component. This can allow remote attackers to execute arbitrary code.
Recommendations For JustSystems Ichitaro versions 2004 through 2007, consider disabling the rich text processing functionality until a patch is available. For JustSystems Ichitaro versions 11 through 13, restrict access to the JSTARO4.OCX and TJSVDA.DLL components to minimize the risk of exploitation. As a temporary workaround, avoid using long pard fields, font names in the fcharset0 field, and long titles in the affected software until the issue is resolved.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5687

Affected Products

Jstaro4.Ocx
Justsystems Ichitaro
Tjsvda.Dll