JustSystems Ichitaro 2005 through 2011, Ichitaro Government 6, Ichitaro Government 2006 through 2010, Ichitaro Portable, Ichitaro Pro, and Ichitaro Viewer allow remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted document, as exploited in the wild in early 2011.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://jvn.jp/en/jp/JVN87239473/index.html - | |
References | () http://jvndb.jvn.jp/jvndb/JVNDB-2011-000043 - | |
References | () http://secunia.com/advisories/44956 - Vendor Advisory | |
References | () http://www.justsystems.com/jp/info/js11001.html - Patch, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/48283 - | |
References | () http://www.symantec.com/connect/blogs/targeted-attacks-2011-using-ichitaro-zero-day-vulnerability - Exploit | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/68072 - |
Information
Published : 2011-07-18 22:55
Updated : 2024-11-21 01:26
NVD link : CVE-2011-1331
Mitre link : CVE-2011-1331
CVE.ORG link : CVE-2011-1331
JSON object : View
Products Affected
justsystems
- ichitaro_viewer
- ichitaro_pro
- ichitaro_portable
- ichitaro
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer