[Japanese]

JVNDB-2010-000066

AttacheCase may insecurely load executable files

Overview

AttacheCase may use unsafe methods for determining how to load executables (.exe).

AttacheCase is a file encryption/decryption software. AttacheCase loads certain executables (.exe) when decrypting files, if certain settings are applied. AttacheCase contains an issue with the file search path, which may insecurely load executables.

Hirotaka Katagiri reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

Base Metrics: 6.8 (Medium) [IPA Score]
  • Access Vector: Network
  • Access Complexity: Medium
  • Authentication: None
  • Confidentiality Impact: Partial
  • Integrity Impact: Partial
  • Availability Impact: Partial

Affected Products


Hibara Software Library
  • AttacheCase ver.2.69 and earlier

Impact

An attacker may execute arbitrary code with the privilege of the running application.
Solution

[Update the Software]
Update to the software according to the information provided by the developer.

Fixed version

* AttacheCase ver.2.70
Vendor Information

Hibara Software Library
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2010-3923
References

  1. JVN : JVN#02175694
  2. National Vulnerability Database (NVD) : CVE-2010-3923
Revision History

[2010/12/17]
  Web page published