CVE-2023-35126

An out-of-bounds write vulnerability exists within the parsers for both the "DocumentViewStyles" and "DocumentEditStyles" streams of Ichitaro 2023 1.0.1.59372 when processing types 0x0000-0x0009 of a style record with the type 0x2008. A specially crafted document can cause memory corruption, which can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:justsystems:easy_postcard_max:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_2021:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_2022:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_2023:1.0.1.59372:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_government_10:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_government_8:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_government_9:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_pro_3:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_pro_4:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_pro_5:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_government_3:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_government_4:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_government_5:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_office_3:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_office_4:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_office_5:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_police_3:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_police_4:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_police_5:-:*:*:*:*:*:*:*

History

25 Oct 2023, 14:48

Type Values Removed Values Added
First Time Justsystems just Office 5
Justsystems ichitaro Pro 3
Justsystems just Police 5
Justsystems ichitaro 2021
Justsystems ichitaro Pro 5
Justsystems ichitaro Government 9
Justsystems easy Postcard Max
Justsystems just Police 3
Justsystems just Office 4
Justsystems ichitaro 2022
Justsystems just Police 4
Justsystems just Government 5
Justsystems ichitaro 2023
Justsystems just Government 4
Justsystems
Justsystems just Office 3
Justsystems ichitaro Government 10
Justsystems just Government 3
Justsystems ichitaro Government 8
Justsystems ichitaro Pro 4
References (MISC) https://jvn.jp/en/jp/JVN28846531/index.html - (MISC) https://jvn.jp/en/jp/JVN28846531/index.html - Third Party Advisory
References (MISC) https://talosintelligence.com/vulnerability_reports/TALOS-2023-1825 - (MISC) https://talosintelligence.com/vulnerability_reports/TALOS-2023-1825 - Exploit, Third Party Advisory
References (MISC) https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1825 - (MISC) https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1825 - Exploit, Third Party Advisory
CWE CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:justsystems:ichitaro_government_8:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_office_3:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_2023:1.0.1.59372:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_office_5:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_police_3:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_police_5:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:easy_postcard_max:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_government_9:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_office_4:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_government_5:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_government_4:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_police_4:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:just_government_3:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_pro_5:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_pro_3:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_pro_4:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_government_10:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_2022:-:*:*:*:*:*:*:*
cpe:2.3:a:justsystems:ichitaro_2021:-:*:*:*:*:*:*:*

19 Oct 2023, 18:15

Type Values Removed Values Added
References
  • (MISC) https://www.talosintelligence.com/vulnerability_reports/TALOS-2023-1825 -

19 Oct 2023, 17:56

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-19 17:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-35126

Mitre link : CVE-2023-35126

CVE.ORG link : CVE-2023-35126


JSON object : View

Products Affected

justsystems

  • ichitaro_2023
  • just_police_3
  • ichitaro_pro_3
  • ichitaro_government_10
  • just_government_5
  • just_police_5
  • just_government_4
  • ichitaro_pro_5
  • just_police_4
  • ichitaro_2022
  • just_office_4
  • easy_postcard_max
  • just_government_3
  • ichitaro_government_9
  • just_office_5
  • ichitaro_government_8
  • just_office_3
  • ichitaro_pro_4
  • ichitaro_2021
CWE
CWE-787

Out-of-bounds Write

CWE-129

Improper Validation of Array Index