CVE-2010-2152
Summary
| CVE | CVE-2010-2152 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-06-03 16:30:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Unspecified vulnerability in JustSystems Ichitaro 2004 through 2009, Ichitaro Government 2006 through 2009, and Just School 2008 and 2009 allows remote attackers to execute arbitrary code via unknown vectors related to "product character attribute processing" for a document. |
Risk And Classification
Primary CVSS: v2.0 9.3 from [email protected]
AV:N/AC:M/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Justsystems | Ichitaro | 2004 | All | All | All |
| Application | Justsystems | Ichitaro | 2005 | All | All | All |
| Application | Justsystems | Ichitaro | 2006 | All | All | All |
| Application | Justsystems | Ichitaro | 2006 | - | government | All |
| Application | Justsystems | Ichitaro | 2007 | All | All | All |
| Application | Justsystems | Ichitaro | 2007 | - | government | All |
| Application | Justsystems | Ichitaro | 2008 | All | All | All |
| Application | Justsystems | Ichitaro | 2008 | - | government | All |
| Application | Justsystems | Ichitaro | 2009 | All | All | All |
| Application | Justsystems | Ichitaro | 2009 | - | government | All |
| Application | Justsystems | Just School | 2008 | All | All | All |
| Application | Justsystems | Just School | 2009 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [JS10002]一太郎の脆弱性を悪用した不正なプログラムの実行危険性について (update: 2010.6.28) | お知らせ | ジャストシステム | af854a3a-2127-422b-91ae-364da2661108 | www.justsystems.com | Patch, Vendor Advisory |
| JustSystems Ichitaro Character Attributes Processing Remote Code Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000024.html | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | |
| プレス発表 「一太郎シリーズ」におけるセキュリティ上の弱点(脆弱性)の注意喚起:IPA 独立行政法人 情報処理推進機構 | af854a3a-2127-422b-91ae-364da2661108 | www.ipa.go.jp | |
| osvdb.org/65050 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| JustSystems Ichitaro Character Attributes Processing Vulnerability - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| JVN#17293765 Ichitaro series vulnerable to arbitrary code execution | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.