Vulnerability Note VU#225833
Iceni products PDF parser stack buffer overflow
Overview
Iceni Argus and Infix contain a stack buffer overflow in the handling of flate-compressed PDF content, which can allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
Description
Iceni Argus is a PDF conversion library. Argus 6.20 and earlier fail to properly handle malformed flate-compressed content in PDF documents, resulting in a stack buffer overflow. Other Argus applications that share the same codebase with Argus may also be affected. We have confirmed that Iceni Infix 5.04 is affected by this vulnerability. |
Impact
By causing the Iceni PDF library to parse a specially-crafted PDF document, a remote, unauthenticated attacker may be able to execute arbitrary code with the privileges of the application using the library. |
Solution
We are currently unaware of a practical solution to this problem. Please consider the following workarounds. |
Use the Microsoft Enhanced Mitigation Experience Toolkit The Microsoft Enhanced Mitigation Experience Toolkit (EMET) can be used to help prevent exploitation of these vulnerabilities. |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| iceni technology | Affected | 06 May 2011 | 05 Oct 2011 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | 9.0 | AV:N/AC:M/Au:N/C:C/I:C/A:P |
| Temporal | 8.1 | E:POC/RL:U/RC:C |
| Environmental | 8.1 | CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND |
References
- http://www.iceni.com/argus.htm
- http://www.microsoft.com/download/en/details.aspx?id=1677
- http://blogs.technet.com/b/srd/archive/2009/06/05/understanding-dep-as-a-mitigation-technology-part-1.aspx
- http://blogs.technet.com/b/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-2.aspx
- http://blogs.technet.com/b/srd/archive/2010/12/08/on-the-effectiveness-of-dep-and-aslr.aspx
- http://secunia.com/advisories/46320/
- http://osvdb.org/76096
- http://xforce.iss.net/xforce/xfdb/70343
- http://www.securityfocus.com/bid/49959
Credit
This vulnerability was reported by Will Dormann of the CERT/CC.
This document was written by Will Dormann.
Other Information
- CVE IDs: CVE-2011-3332
- Date Public: 05 Oct 2011
- Date First Published: 05 Oct 2011
- Date Last Updated: 28 Mar 2012
- Severity Metric: 10.71
- Document Revision: 23
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.