Published:2013/11/12 Last Updated:2013/11/13
JVN#44999463
Ichitaro series vulnerable to arbitrary code execution
Overview
The "Ichitaro" series word processing software, from JustSystems
Corporation contains a vulnerability that may allow arbitrary code
execution.
This vulnerability differs from other issues that were previously published on JVN.
Products Affected
- Ichitaro 2013 Gen
- Ichitaro 2013 Gen Trial Edition
- Ichitaro 2012 Shou
- Ichitaro 2011 Sou / Ichitaro 2011
- Ichitaro Pro 2
- Ichitaro Pro 2 Trial Edition
- Ichitaro Pro
- Ichitaro Government 7
- Ichitaro Government 6
- Ichitaro 2010
- Ichitaro Government 2010
- Ichitaro 2009, Ichitaro Government 2009
- Ichitaro 2008, Ichitaro Government 2008
- Ichitaro 2007, Ichitaro Government 2007
- Ichitaro 2006, Ichitaro Government 2006
- Ichitaro Portable with oreplug
- Ichitaro Viewer
Description
The "Ichitaro" series word processing software, from JustSystems
Corporation contains a vulnerability that may allow arbitrary code
execution.
For more information, please refer to the developer's website.
Impact
When a user opens a specially crafted file, arbitrary code may be executed.
Solution
Update the software
Apply the appropriate update module according to the information provided by the developer.
Vendor Status
Vendor | Link |
JustSystems Corporation | [JS13003] Vulnerability in Ichitaro may allow arbitrary code execution |
References
-
IPA
Security Alert for Vulnerability in the "Ichitaro" series that may allow arbitrary code execution (JVN#44999463)
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Analyzed on 2013.11.12
Measures | Conditions | Severity |
---|---|---|
Access Required | can be attacked over the Internet using packets |
|
Authentication | anonymous or no authentication (IP addresses do not count) |
|
User Interaction Required | the user must be convinced to take a standard action that does not feel harmful to most users, such as click on a link or view a file |
|
Exploit Complexity | expertise and/or luck required (guessing correctly in medium-sized space, kernel expertise) |
|
Credit
Other Information
JPCERT Alert | |
JPCERT Reports | |
CERT Advisory |
|
CPNI Advisory |
|
TRnotes |
|
CVE |
CVE-2013-5990 |
JVN iPedia |
JVNDB-2013-000103 |
Update History
- 2013/11/13
- Information under the section "References" was added.