Multiple buffer overflows in the rich text processing functionality in JustSystems Ichitaro 2004 through 2007, 11 through 13, and other versions allow remote attackers to execute arbitrary code via a long (1) pard field or (2) font name in the fcharset0 field, which is not properly handled in (a) JSTARO4.OCX; or (3) a long title, which is not properly handled by (b) TJSVDA.DLL.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:38
Type | Values Removed | Values Added |
---|---|---|
References | () http://jvn.jp/jp/JVN%2329211062/index.html - | |
References | () http://jvn.jp/jp/JVN%2332981509/index.html - | |
References | () http://jvn.jp/jp/JVN%2350495547/index.html - | |
References | () http://osvdb.org/39394 - | |
References | () http://secunia.com/advisories/27393 - Patch, Vendor Advisory | |
References | () http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20071025-1 - | |
References | () http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20071025-2 - | |
References | () http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20071025-3 - | |
References | () http://www.ipa.go.jp/security/vuln/200710_Ichitaro.html - | |
References | () http://www.justsystems.com/jp/info/pd7004.html - Patch | |
References | () http://www.securityfocus.com/bid/26206 - | |
References | () http://www.vupen.com/english/advisories/2007/3623 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/38129 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/38130 - |
Information
Published : 2007-10-28 17:08
Updated : 2024-11-21 00:38
NVD link : CVE-2007-5687
Mitre link : CVE-2007-5687
CVE.ORG link : CVE-2007-5687
JSON object : View
Products Affected
justsystem
- ichitaro
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer