← Back

CVE-2016-8387

nvd nist
Published: Feb 27, 2017Modified: May 13, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

An exploitable heap-based buffer overflow exists in Iceni Argus. When it attempts to convert a malformed PDF with an object encoded w/ multiple encoding types terminating with an LZW encoded type, an overflow may occur due to a lack of bounds checking by the LZW decoder. This can lead to code execution under the context of the account of the user running it.

Affected (1)

Products: Iceni: Argus
1 product
Argus
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 6.6.04

References (4)

Source: talos-cna@cisco.com
Broken LinkThird Party AdvisoryVDB Entry
Source: talos-cna@cisco.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.