First published: Sun Oct 28 2007(Updated: )
Multiple buffer overflows in the rich text processing functionality in JustSystems Ichitaro 2004 through 2007, 11 through 13, and other versions allow remote attackers to execute arbitrary code via a long (1) pard field or (2) font name in the fcharset0 field, which is not properly handled in (a) JSTARO4.OCX; or (3) a long title, which is not properly handled by (b) TJSVDA.DLL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Justsystems Ichitaro 2017 | =11.0 | |
Justsystems Ichitaro 2017 | =12.0 | |
Justsystems Ichitaro 2017 | =13.0 | |
Justsystems Ichitaro 2017 | =2004 | |
Justsystems Ichitaro 2017 | =2005 | |
Justsystems Ichitaro 2017 | =2006 | |
Justsystems Ichitaro 2017 | =linux | |
Justsystems Ichitaro 2017 | =lite2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5687 has a high severity due to the potential for remote code execution.
To fix CVE-2007-5687, you should update JustSystems Ichitaro to the latest version that addresses this vulnerability.
CVE-2007-5687 affects JustSystems Ichitaro versions 2004 through 2007 and versions 11 through 13.
CVE-2007-5687 can be exploited through buffer overflow attacks via specially crafted rich text files.
Yes, there are known exploits for CVE-2007-5687 that allow attackers to execute arbitrary code.