BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability

BID:44056

Info

BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability

Bugtraq ID: 44056
Class: Boundary Condition Error
CVE: CVE-2010-2601
Remote: Yes
Local: No
Published: Oct 13 2010 12:00AM
Updated: Oct 13 2010 12:00AM
Credit: Research in Motion
Vulnerable: Symantec Clientless VPN Gateway 4400 Series 4.0 SP3
Symantec Clientless VPN Gateway 4400 Series 4.0 SP2
Symantec Clientless VPN Gateway 4400 Series 4.0 SP1
Rim Blackberry Professional Software 4.1.4
Rim Blackberry Enterprise Server for Novell Groupwise 5.0.1
Rim Blackberry Enterprise Server for Novell Groupwise 4.1.7
Rim Blackberry Enterprise Server for Novell Groupwise 4.1
Rim Blackberry Enterprise Server for Novell Groupwise 4.0 SP3 Hotfix 1
Rim Blackberry Enterprise Server for Exchange 4.0 SP1
Rim Blackberry Enterprise Server for Exchange 3.6.1
Rim Blackberry Enterprise Server for Exchange 3.6 SP4 Hot Fix 2
Rim Blackberry Enterprise Server for Exchange 3.6 SP 1a
Rim Blackberry Enterprise Server for Exchange 3.6
Rim Blackberry Enterprise Server for Exchange 3.5
Rim Blackberry Enterprise Server for Exchange 2.1
Rim Blackberry Enterprise Server for Exchange 5.0.2
Rim Blackberry Enterprise Server for Exchange 5.0.1
Rim Blackberry Enterprise Server for Exchange 5.0
Rim Blackberry Enterprise Server for Exchange 4.1.7
Rim Blackberry Enterprise Server for Exchange 4.1
Rim Blackberry Enterprise Server for Exchange 4.0 SP3 Hotfix 3
Rim Blackberry Enterprise Server for Exchange 3.6 SP7
Rim Blackberry Enterprise Server for Domino 4.0
Rim Blackberry Enterprise Server for Domino 2.2 SP4 Hot Fix 2
Rim Blackberry Enterprise Server for Domino 2.2 SP4
Rim Blackberry Enterprise Server for Domino 2.2 SP3a
Rim Blackberry Enterprise Server for Domino 2.2 SP2a
Rim Blackberry Enterprise Server for Domino 2.2 SP2
Rim Blackberry Enterprise Server for Domino 2.2
Rim Blackberry Enterprise Server for Domino 2.1 SP2
Rim Blackberry Enterprise Server for Domino 2.1 SP1
Rim Blackberry Enterprise Server for Domino 2.1
Rim Blackberry Enterprise Server for Domino 5.0.2
Rim Blackberry Enterprise Server for Domino 5.0.1
Rim Blackberry Enterprise Server for Domino 5.0
Rim Blackberry Enterprise Server for Domino 4.1.7
Rim Blackberry Enterprise Server for Domino 4.1 SP3
Rim Blackberry Enterprise Server for Domino 4.0 SP3 Hotfix 4
Rim Blackberry Enterprise Server Express for Exchange 5.0.2
Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 SP3
Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 SP2
Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 SP1
Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0
HP OpenCall MultiService Controller 4.0 SP3
HP OpenCall MultiService Controller 4.0 SP2
HP OpenCall MultiService Controller 4.0
Not Vulnerable:

Discussion

BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability

BlackBerry Attachment Service is prone to a remote buffer-overflow vulnerability when handling specially crafted PDF files.

Attackers can leverage this issue to execute arbitrary code in the context of the vulnerable service, possibly with SYSTEM-level privileges. Successful exploits can compromise the server. Failed attacks will likely result in denial-of-service conditions.

This issue affects the BlackBerry Attachment Service component on the following applications:

BlackBerry Enterprise Server Express for Exchange 5.0.2
BlackBerry Enterprise Server for Exchange 5.0.2, 5.0.1, 4.1.7, and prior
BlackBerry Enterprise Server for Lotus Domino 5.0.2, 5.0.1, 4.1.7, and prior
BlackBerry Enterprise Server for Novell Groupwise 5.0.1, 4.1.7, and prior
BlackBerry Professional Software 4.1.4 and prior

Exploit / POC

BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability

Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

Solution / Fix

BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability

Solution:
Updates are available; please see the references for more information.

References

BlackBerry Attachment Service PDF Distiller Remote Buffer Overflow Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report