CVE-2017-10870
Summary
| CVE | CVE-2017-10870 |
|---|---|
| State | PUBLISHED |
| Assigner | jpcert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-11-02 15:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Memory corruption vulnerability in Rakuraku Hagaki (Rakuraku Hagaki 2018, Rakuraku Hagaki 2017, Rakuraku Hagaki 2016) and Rakuraku Hagaki Select for Ichitaro (Ichitaro 2017, Ichitaro 2016, Ichitaro 2015, Ichitaro Pro3, Ichitaro Pro2, Ichitaro Pro, Ichitaro 2011, Ichitaro Government 8, Ichitaro Government 7, Ichitaro Government 6 and Ichitaro 2017 Trial version) allows attackers to execute arbitrary code with privileges of the application via specially crafted file. |
Risk And Classification
Primary CVSS: v3.0 7.8 HIGH from [email protected]
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Problem Types: CWE-119 | Memory Corrution vulnerability
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Justsystems | Easy Postcard 2016 | - | All | All | All |
| Application | Justsystems | Easy Postcard 2017 | - | All | All | All |
| Application | Justsystems | Easy Postcard 2018 | - | All | All | All |
| Application | Justsystems | Ichitaro 2016 | - | All | All | All |
| Application | Justsystems | Ichitaro 2017 | - | All | All | All |
| Application | Justsystems | Ichitaro 2017 Trial Version | - | All | All | All |
| Application | Justsystems | Ichitaro 2018 | - | All | All | All |
| Application | Justsystems | Ichitaro Government 6 | - | All | All | All |
| Application | Justsystems | Ichitaro Government 7 | - | All | All | All |
| Application | Justsystems | Ichitaro Government 8 | - | All | All | All |
| Application | Justsystems | Ichitaro Pro | - | All | All | All |
| Application | Justsystems | Ichitaro Pro 2 | - | All | All | All |
| Application | Justsystems | Ichitaro Pro 2011 | - | All | All | All |
| Application | Justsystems | Ichitaro Pro 3 | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Justsystem | Rakuraku Hagaki | affected Rakuraku Hagaki 2018 | Not specified |
| CNA | Justsystem | Rakuraku Hagaki | affected Rakuraku Hagaki 2017 | Not specified |
| CNA | Justsystem | Rakuraku Hagaki | affected Rakuraku Hagaki 2016 | Not specified |
| CNA | Justsystem | Rakuraku Hagaki Select For Ichitaro | affected Ichitaro 2017 | Not specified |
| CNA | Justsystem | Rakuraku Hagaki Select For Ichitaro | affected Ichitaro 2016 | Not specified |
| CNA | Justsystem | Rakuraku Hagaki Select For Ichitaro | affected Ichitaro 2015 | Not specified |
| CNA | Justsystem | Rakuraku Hagaki Select For Ichitaro | affected Ichitaro Pro3 | Not specified |
| CNA | Justsystem | Rakuraku Hagaki Select For Ichitaro | affected Ichitaro Pro2 | Not specified |
| CNA | Justsystem | Rakuraku Hagaki Select For Ichitaro | affected Ichitaro Pro | Not specified |
| CNA | Justsystem | Rakuraku Hagaki Select For Ichitaro | affected Ichitaro 2011 | Not specified |
| CNA | Justsystem | Rakuraku Hagaki Select For Ichitaro | affected Ichitaro Government 8 | Not specified |
| CNA | Justsystem | Rakuraku Hagaki Select For Ichitaro | affected Ichitaro Government 7 | Not specified |
| CNA | Justsystem | Rakuraku Hagaki Select For Ichitaro | affected Ichitaro Government 6 | Not specified |
| CNA | Justsystem | Rakuraku Hagaki Select For Ichitaro | affected Ichitaro 2017 Trial version | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [JS17003]楽々はがき および 楽々はがきセレクト for 一太郎の脆弱性を悪用した不正なプログラムの実行危険性について | お知らせ | ジャストシステム | af854a3a-2127-422b-91ae-364da2661108 | www.justsystems.com | Patch, Vendor Advisory |
| JVNVU#93703434: Memory corruption vulnerability in Rakuraku Hagaki and Rakuraku Hagaki Select for Ichitaro | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.