[Japanese] | |
JVNDB-2017-000162 | |
Installer of Douroshisetu Kihon Data Sakusei System may insecurely load Dynamic Link Libraries | |
Overview | |
The installer of Douroshisetu Kihon Data Sakusei System provided by National Institute for Land and Infrastructure Management contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). | |
CVSS Severity (What is CVSS?) | |
CVSS V3 Severity:
Base Metrics 7.8 (High) [IPA Score]
CVSS V2 Severity:
Base Metrics 6.8 (Medium) [IPA Score]
| |
Affected Products | |
| |
Ministry of Land, Infrastructure, Transport and Tourism | |
| |
Impact | |
Arbitrary code may be executed with the privilege of the use invoking the installer. | |
Solution | |
[Apply Workaround] | |
Vendor Information | |
Ministry of Land, Infrastructure, Transport and Tourism | |
CWE (What is CWE?) | |
| |
CVE (What is CVE?) | |
| |
References | |
| |
Revision History | |
|
Date Public | 2017/07/04 |
Date First Published | 2017/07/04 |
Date Last Updated | 2018/02/07 |