CVE-2017-10870
Last modified
CVE-2017-10870 is a vulnerability of currently unknown severity. Memory corruption vulnerability in Rakuraku Hagaki (Rakuraku Hagaki 2018, Rakuraku Hagaki 2017, Rakuraku Hagaki 2016) and Rakuraku Hagaki Select for Ichitaro (Ichitaro 2017, Ichitaro 2016, Ichitaro 2015, Ichitaro Pro3, Ichitaro Pro2, Ichitaro Pro, Ichitaro 2011, Ichitaro Government 8, Ichitaro Government 7, Ichitaro Government 6 and Ichitaro 2017 Trial version) allows attackers to execute arbitrary code with privileges of the application via specially crafted file.. EPSS estimates a 1.31% chance of exploitation in the next 30 days.
Description
Memory corruption vulnerability in Rakuraku Hagaki (Rakuraku Hagaki 2018, Rakuraku Hagaki 2017, Rakuraku Hagaki 2016) and Rakuraku Hagaki Select for Ichitaro (Ichitaro 2017, Ichitaro 2016, Ichitaro 2015, Ichitaro Pro3, Ichitaro Pro2, Ichitaro Pro, Ichitaro 2011, Ichitaro Government 8, Ichitaro Government 7, Ichitaro Government 6 and Ichitaro 2017 Trial version) allows attackers to execute arbitrary code with privileges of the application via specially crafted file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Justsystems | Easy Postcard 2016 | All versions |
| Justsystems | Easy Postcard 2017 | All versions |
| Justsystems | Easy Postcard 2018 | All versions |
| Justsystems | Ichitaro 2016 | All versions |
| Justsystems | Ichitaro 2017 | All versions |
| Justsystems | Ichitaro 2017 Trial Version | All versions |
| Justsystems | Ichitaro 2018 | All versions |
| Justsystems | Ichitaro Government 6 | All versions |
| Justsystems | Ichitaro Government 7 | All versions |
| Justsystems | Ichitaro Government 8 | All versions |
| Justsystems | Ichitaro Pro | All versions |
| Justsystems | Ichitaro Pro 2 | All versions |
| Justsystems | Ichitaro Pro 2011 | All versions |
| Justsystems | Ichitaro Pro 3 | All versions |
References
- https://jvn.jp/en/vu/JVNVU93703434/index.htmlThird Party Advisory, VDB Entry
- https://www.justsystems.com/jp/info/js17003.htmlPatch, Vendor Advisory
- https://jvn.jp/en/vu/JVNVU93703434/index.htmlThird Party Advisory, VDB Entry
- https://www.justsystems.com/jp/info/js17003.htmlPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-10870?
How severe is CVE-2017-10870?
How do I fix CVE-2017-10870?
Are you affected by CVE-2017-10870?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
