Let us know your comment and
information on the Badkey.com
site
Tuesday 22nd, July 2008
Vulnerability: Upgrade to BES v4.1 SP6 (4.1.6)07/22/2008 10:19 PM
Vulnerability:
In the PDF distiller of the BlackBerry Attachment Service for the BlackBerry Enterprise Server. Upgrade to BlackBerry Enterprise Server software version 4.1 Service Pack 6 ( Version 4.1.6 )
Overview: This advisory describes a security issue that the BlackBerry Attachment Service component of the BlackBerry Enterprise Server is susceptible to.
The issue relates to a known vulnerability in the PDF distiller component of the BlackBerry Attachment Service that affects how the BlackBerry Attachment Service processes PDF files.
This vulnerability has a Common Vulnerability Scoring System (CVSS) score of 9.0.
Problem: A security vulnerability exists in the PDF distiller of some released versions of the BlackBerry Attachment Service. This vulnerability could enable a malicious individual to send an email message containing a specially crafted PDF file, which when opened for viewing on a BlackBerry smartphone, could cause memory corruption and possibly lead to arbitrary code execution on the computer that the BlackBerry Attachment Service runs on.
Resolution: Upgrade to BlackBerry Enterprise Server software version 4.1 Service Pack 6 (4.1.6).
Research In Motion (RIM) has also issued an interim security software update that resolves this vulnerability in earlier affected versions of the BlackBerry Enterprise Server and BlackBerry Professional Software.