[Japanese]
|
JVNDB-2012-000035
|
Multiple JustSystems products vulnerable to buffer overflow
|
Multiple products provided by JustSystems Corporation contain a buffer overflow vulnerability.
Multiple products provided by JustSystems Corporation contain a buffer overflow vulnerability due to improper handling of image files.
Tielei Wang of Georgia Tech Information Security Center reported this vulnerability to JPCERT/CC via The Secunia Vulnerability Coordination Reward Programme (SVCRP).
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 6.8 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: Partial
|
|
JustSystems Corporation
- Shuriken 2010
- Shuriken 2009
- Shuriken 2008
- Shuriken 2007
- Shuriken Pro4
- Shuriken 2010 CE
- Shuriken 2009 CE
- Shuriken 2008 CE
- Shuriken 2007 [Corporate Edition]
- Shuriken Pro4 [Corporate Edition]
- Just Jump 4
- Just School 2010
- Just School 2009
- Just School
- Just Frontier
- Ichitaro 2011
- Ichitaro 2010
- Ichitaro 2009
- Ichitaro 2008
- Ichitaro 2007
- Ichitaro 2006
- Ichitaro 2011 Sou
- Ichitaro 2012 Shou
- Ichitaro Government 2010
- Ichitaro Government 2009
- Ichitaro Government 2008
- Ichitaro Government 2007
- Ichitaro Government 2006
- Ichitaro Viewer
- Ichitaro Portable with oreplug
- Rekishimail Sengokubusho no missho
- Rekishimail Bakumatsushishi no missho
- oreplug
|
|
If this vulnerability is exploited, a system may be crashed or arbitrary code may be executed.
|
[Update the Software]
Apply the appropriate update according to the information provided by the developer.
|
JustSystems Corporation
|
- Numeric Errors(CWE-189) [IPA Evaluation]
|
- CVE-2012-0269
|
- JVN : JVN#09619876
- National Vulnerability Database (NVD) : CVE-2012-0269
- IPA SECURITY ALERTS : Security Alert for Vulnerability in Multiple JustSystems Products
- Secunia Advisory : SA47363 JustSystems Multiple Products Two Vulnerabilities
|
- [2012/04/24]
Web page was published
[2012/05/09]
Affected Products : JustSystems Corporation was updated.
|