Blog | G5 Cyber Security

Vulnerability Spotlight: Iceni Argus Buffer Overflows

Vulnerabilities discovered by Marcin ‘Icewall’ Noga of Cisco Talos. Both vulnerabilities occur in the PDF to html converter functionality of Iceni Argus. An attacker can send or provide a specially crafted pdf file that can cause a buffer overflow to trigger either of these vulnerabilities resulting in arbitrary code execution. The software is used to convert a pdf document into various tagged and xml-based formats (such as XHTML) Software, such as MarkLogic, uses it for pdf document conversions as part of their web based document rendering.”]

Source: https://blog.talosintelligence.com/2016/10/iceni-argus.html

Exit mobile version