← Back

CVE-2014-2003

nvd nist
Published: Jun 16, 2014Modified: May 6, 2026

JSON object

Loading...
7.6
Vector
AV:N/AC:H/Au:N/C:C/I:C/A:C
Exploitability: 4.9 / Impact: 10.0
Source: NVD

Description

JustSystems JUST Online Update, as used in Ichitaro through 2014 and other products, does not properly validate signatures of update modules, which allows remote attackers to spoof modules and execute arbitrary code via a crafted signature.

Affected (24)

2 products
Ichitaro
Just Online Update
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Justsystems
Up to 2014
Version 10
Version 11
Version 12
Version 13
Version 2004
Version 2005
Version 2006
Version 2006
Version 2007
Version 2007
Version 2008
Version 2008
Version 2009
Version 2009
Version 2009
Version 2010
Version 2010
Version 2011
Version 2011
Version 2012
Version 2013
Version 2013
All versions

References (8)

Source: vultures@jpcert.or.jp
Source: vultures@jpcert.or.jp
Source: vultures@jpcert.or.jp
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.