PT-2017-9655 · Iceni · Iceni Argus

Published

2017-02-28

·

Updated

2022-12-14

·

CVE-2016-8389

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Iceni Argus (affected versions not specified)
Description An integer-overflow issue exists when Iceni Argus attempts to convert a malformed PDF to XML. The application tries to convert each character from a font into a polygon and then rasterize these shapes. As it iterates through the rows and initializes the polygon shape in the buffer, it writes outside the buffer bounds, potentially leading to code execution under the context of the account running it.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2016-8389

Affected Products

Iceni Argus