34405Third-party advisory
http://secunia.com/advisories/34405 CVE-2009-1054
JustSystems Ichitaro 13, 2004 through 2008, Lite2, and Ichitaro viewer 5.1.5.0 and earlier Remote Code Execution
Record summary
CVE-2009-1054 has a selected CVSS score of 9.3.
Description
Unspecified vulnerability in JustSystems Ichitaro 13, 2004 through 2008, Lite2, and Ichitaro viewer 5.1.5.0 and earlier allows remote attackers to execute arbitrary code via a crafted file, as exploited in the wild by Trojan.Tarodrop.H in March 2009.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 24, 2009 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ichitaroBrowse ichitaro / ichitaro | VulnCheck | Version data not supplied | |
References
7justsystems.comConfirmation
http://www.justsystems.com/jp/info/js09001.html 34138vdb entry
http://www.securityfocus.com/bid/34138 symantec.com
http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-031608-2424-99 ADV-2009-0769vdb entry
http://www.vupen.com/english/advisories/2009/0769 ichitaro-webpuraguinbyua-code-execution(49280)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/49280 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-1054