BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability
BID:44056
Info
BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 44056 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-2601 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 13 2010 12:00AM |
| Updated: | Oct 13 2010 12:00AM |
| Credit: | Research in Motion |
| Vulnerable: |
Symantec Clientless VPN Gateway 4400 Series 4.0 SP3 Symantec Clientless VPN Gateway 4400 Series 4.0 SP2 Symantec Clientless VPN Gateway 4400 Series 4.0 SP1 Rim Blackberry Professional Software 4.1.4 Rim Blackberry Enterprise Server for Novell Groupwise 5.0.1 Rim Blackberry Enterprise Server for Novell Groupwise 4.1.7 Rim Blackberry Enterprise Server for Novell Groupwise 4.1 Rim Blackberry Enterprise Server for Novell Groupwise 4.0 SP3 Hotfix 1 Rim Blackberry Enterprise Server for Exchange 4.0 SP1 Rim Blackberry Enterprise Server for Exchange 3.6.1 Rim Blackberry Enterprise Server for Exchange 3.6 SP4 Hot Fix 2 Rim Blackberry Enterprise Server for Exchange 3.6 SP 1a Rim Blackberry Enterprise Server for Exchange 3.6 Rim Blackberry Enterprise Server for Exchange 3.5 Rim Blackberry Enterprise Server for Exchange 2.1 Rim Blackberry Enterprise Server for Exchange 5.0.2 Rim Blackberry Enterprise Server for Exchange 5.0.1 Rim Blackberry Enterprise Server for Exchange 5.0 Rim Blackberry Enterprise Server for Exchange 4.1.7 Rim Blackberry Enterprise Server for Exchange 4.1 Rim Blackberry Enterprise Server for Exchange 4.0 SP3 Hotfix 3 Rim Blackberry Enterprise Server for Exchange 3.6 SP7 Rim Blackberry Enterprise Server for Domino 4.0 Rim Blackberry Enterprise Server for Domino 2.2 SP4 Hot Fix 2 Rim Blackberry Enterprise Server for Domino 2.2 SP4 Rim Blackberry Enterprise Server for Domino 2.2 SP3a Rim Blackberry Enterprise Server for Domino 2.2 SP2a Rim Blackberry Enterprise Server for Domino 2.2 SP2 Rim Blackberry Enterprise Server for Domino 2.2 Rim Blackberry Enterprise Server for Domino 2.1 SP2 Rim Blackberry Enterprise Server for Domino 2.1 SP1 Rim Blackberry Enterprise Server for Domino 2.1 Rim Blackberry Enterprise Server for Domino 5.0.2 Rim Blackberry Enterprise Server for Domino 5.0.1 Rim Blackberry Enterprise Server for Domino 5.0 Rim Blackberry Enterprise Server for Domino 4.1.7 Rim Blackberry Enterprise Server for Domino 4.1 SP3 Rim Blackberry Enterprise Server for Domino 4.0 SP3 Hotfix 4 Rim Blackberry Enterprise Server Express for Exchange 5.0.2 Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 SP3 Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 SP2 Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 SP1 Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 HP OpenCall MultiService Controller 4.0 SP3 HP OpenCall MultiService Controller 4.0 SP2 HP OpenCall MultiService Controller 4.0 |
| Not Vulnerable: | |
Discussion
BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability
BlackBerry Attachment Service is prone to a remote buffer-overflow vulnerability when handling specially crafted PDF files.
Attackers can leverage this issue to execute arbitrary code in the context of the vulnerable service, possibly with SYSTEM-level privileges. Successful exploits can compromise the server. Failed attacks will likely result in denial-of-service conditions.
This issue affects the BlackBerry Attachment Service component on the following applications:
BlackBerry Enterprise Server Express for Exchange 5.0.2
BlackBerry Enterprise Server for Exchange 5.0.2, 5.0.1, 4.1.7, and prior
BlackBerry Enterprise Server for Lotus Domino 5.0.2, 5.0.1, 4.1.7, and prior
BlackBerry Enterprise Server for Novell Groupwise 5.0.1, 4.1.7, and prior
BlackBerry Professional Software 4.1.4 and prior
BlackBerry Attachment Service is prone to a remote buffer-overflow vulnerability when handling specially crafted PDF files.
Attackers can leverage this issue to execute arbitrary code in the context of the vulnerable service, possibly with SYSTEM-level privileges. Successful exploits can compromise the server. Failed attacks will likely result in denial-of-service conditions.
This issue affects the BlackBerry Attachment Service component on the following applications:
BlackBerry Enterprise Server Express for Exchange 5.0.2
BlackBerry Enterprise Server for Exchange 5.0.2, 5.0.1, 4.1.7, and prior
BlackBerry Enterprise Server for Lotus Domino 5.0.2, 5.0.1, 4.1.7, and prior
BlackBerry Enterprise Server for Novell Groupwise 5.0.1, 4.1.7, and prior
BlackBerry Professional Software 4.1.4 and prior
Exploit / POC
BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability
References:
References:
- Vendor Homepage (Research In Motion)
- KB24547 Vulnerability in the PDF distiller of the BlackBerry Attachment Service (Research in Motion)