PT-2017-9655 · Iceni · Iceni Argus
Published
2017-02-28
·
Updated
2022-12-14
·
CVE-2016-8389
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Iceni Argus (affected versions not specified)
Description
An integer-overflow issue exists when Iceni Argus attempts to convert a malformed PDF to XML. The application tries to convert each character from a font into a polygon and then rasterize these shapes. As it iterates through the rows and initializes the polygon shape in the buffer, it writes outside the buffer bounds, potentially leading to code execution under the context of the account running it.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iceni Argus