PatchSiren cyber security CVE debrief
CVE-2016-8387 Iceni CVE debrief
CVE-2016-8387 describes a heap-based buffer overflow in Iceni Argus while converting malformed PDF content. According to NVD, the issue is triggered when an object encoded with multiple encoding types ends with an LZW-encoded type, and the overflow stems from missing bounds checking in the LZW decoder. The impact is rated High, with the potential for code execution under the context of the user running the application.
- Vendor
- Iceni
- Product
- Argus
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-27
- Advisory updated
- 2026-05-13
Who should care
Organizations and individuals using Iceni Argus 6.6.04, especially workflows that open or convert untrusted PDFs. Security teams should care because the flaw can be triggered during document processing and may lead to code execution in the user context.
Technical summary
NVD maps the vulnerability to CWE-787 (out-of-bounds write) and identifies Iceni Argus 6.6.04 as vulnerable. The CVSS v3.1 vector is AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating local exploitation with user interaction required and high potential impact. The described failure mode is a heap-based buffer overflow in the LZW decoder when processing a malformed PDF object that uses multiple encoding types and ends in LZW encoding. The supplied corpus does not include a vendor patch advisory or fixed version.
Defensive priority
High. Although user interaction is required, the impact is severe and the vulnerable operation is document parsing, a common attack surface for malicious files.
Recommended defensive actions
- Inventory systems running Iceni Argus and confirm whether version 6.6.04 is present.
- Avoid processing untrusted or unsolicited PDFs in Iceni Argus until a fixed version or vendor guidance is confirmed.
- Run PDF conversion in a sandboxed, least-privilege environment to reduce impact if malformed content is encountered.
- Monitor for crashes or abnormal behavior during PDF conversion workflows, which may indicate malformed input handling issues.
- Follow the linked vendor/third-party advisory references for remediation guidance and any available updates.
Evidence notes
The NVD record supplied in the corpus states that the issue affects Iceni Argus 6.6.04, is caused by a lack of bounds checking in the LZW decoder, and maps to CWE-787. The NVD metadata also provides the CVSS v3.1 vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. The corpus includes third-party advisory references from Talos/Cisco, but no advisory text or vendor fix details are included here.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-8387 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-8387
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-8387 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-8387
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.