Description: Yuu Arai has discovered a vulnerability in various JustSystems products, which potentially can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to an unspecified error when handling document properties (e.g. "Keyword" and "Title") and can be exploited to cause a buffer overflow when a specially crafted document is opened.
Successful exploitation may allow execution of arbitrary code.
The vulnerability is reported in the following products:
* Ichitaro 2005
* Ichitaro 2004
* Ichitaro viewer 4.0
* Hanako 2006
* Hanako 2005
* Hanako 2004
* Hanako viewer 1.0
* Sanshiro 2005
* Ichitaro Lite2 /R.2
* Ichitaro Lite2
Solution: Apply patch (see the vendor's advisory).
Provided and/or discovered by: Yuu Arai, LAC
Changelog: 2006-12-06: Added additional information from LAC Little eArth Corporation.
2006-12-11: Added CVE reference.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.