Title : JustSystems Ichitaro "JSGCI.DLL" Library Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-4213 CVE ID : CVE-2007-6436
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-13
Technical Description
A vulnerability has been identified in JustSystems Ichitaro, which could be exploited by attackers to take complete control of an affected system. This issue is caused by a buffer overflow error in the "JSGCI.DLL" library when processing malformed data, which could be exploited by attackers to crash a vulnerable application or execute arbitrary commands by tricking a user into opening a specially crafted document.
Note: This vulnerability is currently being exploited in the wild by Trojan.Tarodrop.F.