CVE-2023-38127: Justsystems Easy Postcard Max
High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.
An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Affected products
- Justsystems Easy Postcard Max: affected versions not specified
- Justsystems Ichitaro 2021: affected versions not specified
- Justsystems Ichitaro 2022: affected versions not specified
- Justsystems Ichitaro 2023: version 1.0.1.59372 only
- Justsystems Ichitaro Government 10: affected versions not specified
- Justsystems Ichitaro Government 8: affected versions not specified
- Justsystems Ichitaro Government 9: affected versions not specified
- Justsystems Ichitaro Pro 3: affected versions not specified
- Justsystems Ichitaro Pro 4: affected versions not specified
- Justsystems Ichitaro Pro 5: affected versions not specified
- Justsystems Just Government 3: affected versions not specified
- Justsystems Just Government 4: affected versions not specified
- Justsystems Just Government 5: affected versions not specified
- Justsystems Just Office 3: affected versions not specified
- Justsystems Just Office 4: affected versions not specified
- Justsystems Just Office 5: affected versions not specified
- Justsystems Just Police 3: affected versions not specified
- Justsystems Just Police 4: affected versions not specified
- Justsystems Just Police 5: affected versions not specified
Published 2023-10-19. Last modified 2026-06-17.