First published: Thu Oct 19 2023(Updated: )
An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Justsystems Easy Postcard Max | ||
Justsystems Ichitaro | ||
Justsystems Ichitaro 2022 | ||
Justsystems Ichitaro 2023 | =1.0.1.59372 | |
Justsystems Ichitaro Government 10 | ||
Justsystems Ichitaro Government 8 | ||
Justsystems Ichitaro Government 9 | ||
Justsystems Ichitaro Pro 3 | ||
Justsystems Ichitaro Pro 4 | ||
Justsystems Ichitaro Pro 5 | ||
Justsystems Just Government | ||
Justsystems Just Government | ||
Justsystems Just Government | ||
Justsystems Just Office 3 | ||
Justsystems Just Office 4 | ||
Justsystems Just Office 5 | ||
Justsystems Just Police 3 | ||
Justsystems Just Police 4 | ||
Justsystems Just Police 5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38127 is considered a high severity vulnerability due to its potential for memory corruption and arbitrary code execution.
To fix CVE-2023-38127, you should update to the latest version of affected software from Justsystems that addresses this vulnerability.
CVE-2023-38127 affects multiple versions of Justsystems Ichitaro, Easy Postcard Max, and Just Office products.
CVE-2023-38127 is an integer overflow vulnerability found in the HyperLinkFrame stream parser.
Yes, CVE-2023-38127 can lead to remote attacks by allowing an attacker to execute arbitrary code through specially crafted documents.