PT-2017-11573 · Justsystems · Rakuraku Hagaki+9

Published

2017-11-02

·

Updated

2017-11-22

·

CVE-2017-10870

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Rakuraku Hagaki versions 2016 through 2018 Rakuraku Hagaki Select for Ichitaro versions 2011 through 2017 Ichitaro versions 2011 through 2017 Ichitaro Pro3 Ichitaro Pro2 Ichitaro Pro Ichitaro Government 8 Ichitaro Government 7 Ichitaro Government 6 Ichitaro 2017 Trial version
Description A memory corruption issue allows attackers to execute arbitrary code with the privileges of the application via specially crafted files.
Recommendations For Rakuraku Hagaki versions 2016 through 2018, update to a version that includes the fix for this issue. For Rakuraku Hagaki Select for Ichitaro versions 2011 through 2017, update to a version that includes the fix for this issue. For Ichitaro versions 2011 through 2017, update to a version that includes the fix for this issue. For Ichitaro Pro3, Ichitaro Pro2, Ichitaro Pro, Ichitaro Government 8, Ichitaro Government 7, Ichitaro Government 6, and Ichitaro 2017 Trial version, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting the use of specially crafted files until a patch is available.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-10870

Affected Products

Ichitaro
Ichitaro 2017 Trial Version
Ichitaro Government 6
Ichitaro Government 7
Ichitaro Government 8
Ichitaro Pro
Ichitaro Pro2
Ichitaro Pro3
Rakuraku Hagaki
Rakuraku Hagaki Select For Ichitaro