CVE-2017-2789
Last modified
CVE-2017-2789 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. When copying filedata into a buffer, JustSystems Ichitaro Office 2016 Trial will calculate two values to determine how much data to copy from the document. If both of these values are larger than the size of the buffer, the application will choose the smaller of the two and trust it to copy data from the file. EPSS estimates a 2.34% chance of exploitation in the next 30 days.
Description
When copying filedata into a buffer, JustSystems Ichitaro Office 2016 Trial will calculate two values to determine how much data to copy from the document. If both of these values are larger than the size of the buffer, the application will choose the smaller of the two and trust it to copy data from the file. This value is larger than the buffer size, which leads to a heap-based buffer overflow. This overflow corrupts an offset in the heap used in pointer arithmetic for writing data and can lead to code execution under the context of the application.
Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Justsystems | Ichitaro | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-2789?
How severe is CVE-2017-2789?
How do I fix CVE-2017-2789?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-2783An exploitable heap corruption vulnerability exists in the F…8.3
- CVE-2017-2784An exploitable free of a stack pointer vulnerability exists …8.1
- CVE-2017-2785An exploitable buffer overflow exists in the psnotifyd appli…10
- CVE-2017-2786A denial of service vulnerability exists in the psnotifyd ap…7.5
- CVE-2017-2787A buffer overflows exists in the psnotifyd application of th…9
- CVE-2017-2788A buffer overflows exists in the psnotifyd application of th…10
- CVE-2017-2790When processing a record type of 0x3c from a Workbook stream…8.8
- CVE-2017-2791JustSystems Ichitaro 2016 Trial contains a vulnerability tha…7.5
- CVE-2017-2792An exploitable heap corruption vulnerability exists in the i…8.3
- CVE-2017-2793An exploitable heap corruption vulnerability exists in the U…8.3
- CVE-2017-2794An exploitable stack-based buffer overflow vulnerability exi…8.3
- CVE-2017-2795An exploitable heap corruption vulnerability exists in the T…8.3
Are you affected by CVE-2017-2789?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
