Secunia Logo  
 
JustSystems Multiple Products Buffer Overflow Vulnerability
Secunia Advisory: SA23185
Release Date: 2006-12-05
Last Update: 2006-12-11
Popularity: 7,432 views

Critical:
Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

Software:Hanako 2004
Hanako 2005
Hanako 2006
Hanako viewer 1.x
Ichitaro 2004
Ichitaro 2005
Ichitaro Lite2
Ichitaro viewer 4.x
Sanshiro 2005

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2006-6400


Description:
Yuu Arai has discovered a vulnerability in various JustSystems products, which potentially can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an unspecified error when handling document properties (e.g. "Keyword" and "Title") and can be exploited to cause a buffer overflow when a specially crafted document is opened.

Successful exploitation may allow execution of arbitrary code.

The vulnerability is reported in the following products:
* Ichitaro 2005
* Ichitaro 2004
* Ichitaro viewer 4.0
* Hanako 2006
* Hanako 2005
* Hanako 2004
* Hanako viewer 1.0
* Sanshiro 2005
* Ichitaro Lite2 /R.2
* Ichitaro Lite2

Solution:
Apply patch (see the vendor's advisory).

Provided and/or discovered by:
Yuu Arai, LAC

Changelog:
2006-12-06: Added additional information from LAC Little eArth Corporation.
2006-12-11: Added CVE reference.

Original Advisory:
JustSystems:
http://www.justsystem.co.jp/info/pd6005.html

LAC Little eArth Corporation:
http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/92_e.html

Other References:
JVN:
http://jvn.jp/jp/JVN%2347272891/index.html


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Internet Explorer Data Binding Memory Corruption Vulnerability // 43 views
2. Cisco Global Site Selector DNS Request Denial of Service // 36 views
3. Drupal Project Module File Upload and Cross-Site Scripting // 30 views
4. Sun Java JDK / JRE Multiple Vulnerabilities // 29 views
5. phpBB Avatar Functions Information Disclosure and Deletion // 27 views
6. NTP OpenSSL "EVP_VerifyFinal()" Spoofing Vulnerability // 26 views
7. SmbFTPD Long Command Processing Vulnerability // 24 views
8. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 24 views
9. Red Hat update for openssl // 23 views
10. tnftpd Long Command Processing Vulnerability // 23 views