PermaLink Vulnerability: Upgrade to BES v4.1 SP6 (4.1.6)07/22/2008 10:19 PM
Vulnerability:

In the PDF distiller of the BlackBerry Attachment Service for the BlackBerry Enterprise Server. Upgrade to BlackBerry Enterprise Server software version 4.1 Service Pack 6 ( Version 4.1.6 )

Overview:
This advisory describes a security issue that the BlackBerry Attachment Service component of the BlackBerry Enterprise Server is susceptible to.
The issue relates to a known vulnerability in the PDF distiller component of the BlackBerry Attachment Service that affects how the BlackBerry Attachment Service processes PDF files.

This vulnerability has a Common Vulnerability Scoring System (CVSS) score of 9.0.

Problem:
A security vulnerability exists in the PDF distiller of some released versions of the BlackBerry Attachment Service. This vulnerability could enable a malicious individual to send an email message containing a specially crafted PDF file, which when opened for viewing on a BlackBerry smartphone, could cause memory corruption and possibly lead to arbitrary code execution on the computer that the BlackBerry Attachment Service runs on.

Resolution:
Upgrade to BlackBerry Enterprise Server software version 4.1 Service Pack 6 (4.1.6).

Research In Motion (RIM) has also issued an interim security software update that resolves this vulnerability in earlier affected versions of the BlackBerry Enterprise Server and BlackBerry Professional Software.

More @blackberry.com


Technorati:
Domino Support
ClusterMaps
Locations of visitors to this page
MRTG @Badkey
Domino/Lotus Forums
About Badkey Corner
Linux Links
Domino Information
Sponsor Google Ads
Promotion Engines
Wiki Links
Private links
Development @Badkey
Domino Jobs
Photo Albums
Development Beta @Badkey
John Willemse
Powered By ND8
nd8-block.jpg
Linked In
View John Willemse's profile on LinkedIn
Search
StatCounter Statistics

View My Stats
Visitor Activity
Google Search Page
Google
Badkey Technical
Search the Engines
Google Badkey
By Category
News and Search
Add to Google
Add to Google
Badkey Legal
Google AdSence
Podcast
Reading via RSS
Anti-Spam
Network Information
Virus Information
Security Information
DNSBLs Domain Blocks
Google Analytics
Analytics blogspot
Ego Surf
Meta Tags References
Timer Count Down LS9
5 Years from now

Just a Valentine
My birthday 2009