Netskope Threat Labs

FILE-PDF Iceni Argus ipStringCreate integer overflow attempt

IPS-SWG

1 SID: 41327

First seen
January 2025
Last seen
February 2025

Detects a PDF exploiting CVE-2017-2777, an integer overflow in the Iceni Argus PDF conversion engine that can allow code execution. The rule matches the crafted string allocations that overflow length calculations in the converter's parser.