60
CVE-2023-38127
PoC —CVSS 3.1
7.8 high
EPSS
<1%p49
Published
()
Modified
Description
An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
- Vendors
- justsystems
- Products
- easy postcard max, ichitaro 2021, ichitaro 2022, ichitaro 2023, ichitaro government 10, ichitaro government 8, ichitaro government 9, ichitaro pro 3, ichitaro pro 4, ichitaro pro 5, just government 3, just government 4
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H