BlackBerry Attachment Service PDF Distiller Uninitialized Heap Memory Code Execution Vulnerability
BID:33250
Info
BlackBerry Attachment Service PDF Distiller Uninitialized Heap Memory Code Execution Vulnerability
| Bugtraq ID: | 33250 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-0219 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 12 2009 12:00AM |
| Updated: | Jan 23 2009 06:12PM |
| Credit: | Sean Larsson of iDefense Labs |
| Vulnerable: |
Rim Blackberry Unite! 1.0.1 bundle 36 Rim Blackberry Unite! 1.0.1 Rim Blackberry Unite! 1.0 Rim Blackberry Professional Software 4.1.4 Rim Blackberry Enterprise Server 4.1.6 Rim Blackberry Enterprise Server 4.1.5 Rim Blackberry Enterprise Server 4.1.4 Rim Blackberry Enterprise Server 4.1.3 |
| Not Vulnerable: |
Rim Blackberry Unite! 1.0.3 bundle 28 |
Discussion
BlackBerry Attachment Service PDF Distiller Uninitialized Heap Memory Code Execution Vulnerability
BlackBerry Attachment Service is prone to a remote code-execution vulnerability when handling specially crafted PDF files.
Attackers can leverage this issue to execute arbitrary machine code in the context of the vulnerable service, possibly with SYSTEM-level privileges. Successful exploits will compromise the server. Failed attacks will likely result in denial-of-service conditions.
NOTE: This issue was originally included in BID 33224 (BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability), but has been given its own entry to better document the issue.
This issue affects the following:
BlackBerry Enterprise Server 4.1.3 through 4.1.6
BlackBerry Unite! prior to 1.0 SP3 bundle 28
BlackBerry Professional Software 4.1.4
BlackBerry Attachment Service is prone to a remote code-execution vulnerability when handling specially crafted PDF files.
Attackers can leverage this issue to execute arbitrary machine code in the context of the vulnerable service, possibly with SYSTEM-level privileges. Successful exploits will compromise the server. Failed attacks will likely result in denial-of-service conditions.
NOTE: This issue was originally included in BID 33224 (BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability), but has been given its own entry to better document the issue.
This issue affects the following:
BlackBerry Enterprise Server 4.1.3 through 4.1.6
BlackBerry Unite! prior to 1.0 SP3 bundle 28
BlackBerry Professional Software 4.1.4
Exploit / POC
BlackBerry Attachment Service PDF Distiller Uninitialized Heap Memory Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
BlackBerry Attachment Service PDF Distiller Uninitialized Heap Memory Code Execution Vulnerability
Solution:
BlackBerry Unite! 1.0.3 bundle 28 has been released to address this issue. Interim fixes are available for Enterprise Server and Professional Software. Please contact the vendor for details.
Solution:
BlackBerry Unite! 1.0.3 bundle 28 has been released to address this issue. Interim fixes are available for Enterprise Server and Professional Software. Please contact the vendor for details.
References
BlackBerry Attachment Service PDF Distiller Uninitialized Heap Memory Code Execution Vulnerability
References:
References:
- RIM BlackBerry Enterprise Server Attachment Service PDF Distiller Uninitialized (iDefense Labs)
- Vendor Homepage (Research In Motion)
- iDefense Security Advisory 01.13.09: RIM BlackBerry Enterprise Server Attachment (iDefense Labs
) - Vulnerabilities in the PDF distiller of the BlackBerry Attachment Service for Bl (Research in Motion)
- Vulnerabilities in the PDF distiller of the BlackBerry Attachment Service for th (Research in Motion)