An out-of-bounds write vulnerability exists within the parsers for both the "DocumentViewStyles" and "DocumentEditStyles" streams of Ichitaro 2023 1.0.1.59372 when processing types 0x0000-0x0009 of a style record with the type 0x2008. A specially crafted document can cause memory corruption, which can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Justsystems
Subscribe
|
Easy Postcard Max
Subscribe
Ichitaro 2021
Subscribe
Ichitaro 2022
Subscribe
Ichitaro 2023
Subscribe
Ichitaro Government 10
Subscribe
Ichitaro Government 8
Subscribe
Ichitaro Government 9
Subscribe
Ichitaro Pro 3
Subscribe
Ichitaro Pro 4
Subscribe
Ichitaro Pro 5
Subscribe
Just Government 3
Subscribe
Just Government 4
Subscribe
Just Government 5
Subscribe
Just Office 3
Subscribe
Just Office 4
Subscribe
Just Office 5
Subscribe
Just Police 3
Subscribe
Just Police 4
Subscribe
Just Police 5
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-39159 | An out-of-bounds write vulnerability exists within the parsers for both the "DocumentViewStyles" and "DocumentEditStyles" streams of Ichitaro 2023 1.0.1.59372 when processing types 0x0000-0x0009 of a style record with the type 0x2008. A specially crafted document can cause memory corruption, which can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 14 Feb 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2025-02-13T16:55:47.722Z
Reserved: 2023-07-31T21:52:03.187Z
Link: CVE-2023-35126
Updated: 2024-08-02T16:23:59.476Z
Status : Modified
Published: 2023-10-19T17:15:10.000
Modified: 2024-11-21T08:07:59.467
Link: CVE-2023-35126
No data.
OpenCVE Enrichment
No data.
EUVD