An invalid free vulnerability exists in the Frame stream parser functionality of Ichitaro 2022 1.0.1.57600. A specially crafted document can lead to an attempt to free a stack pointer, which causes memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
The product calls free() on a pointer to memory that was not allocated using associated heap allocation functions such as malloc(), calloc(), or realloc().
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1687 | third party advisory exploit |
https://jvn.jp/en/jp/JVN79149117/ | third party advisory vdb entry |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1687 |