An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Justsystems
Subscribe
|
Easy Postcard Max
Subscribe
Ichitaro 2021
Subscribe
Ichitaro 2022
Subscribe
Ichitaro 2023
Subscribe
Ichitaro Government 10
Subscribe
Ichitaro Government 8
Subscribe
Ichitaro Government 9
Subscribe
Ichitaro Pro 3
Subscribe
Ichitaro Pro 4
Subscribe
Ichitaro Pro 5
Subscribe
Just Government 3
Subscribe
Just Government 4
Subscribe
Just Government 5
Subscribe
Just Office 3
Subscribe
Just Office 4
Subscribe
Just Office 5
Subscribe
Just Police 3
Subscribe
Just Police 4
Subscribe
Just Police 5
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-41953 | An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2025-11-04T19:17:16.966Z
Reserved: 2023-07-17T21:54:43.843Z
Link: CVE-2023-38127
Updated: 2024-08-02T17:30:13.946Z
Status : Modified
Published: 2023-10-19T18:15:09.467
Modified: 2025-11-04T20:16:33.990
Link: CVE-2023-38127
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD