Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 up to and including 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! prior to 1.0.3 bundle 28 allow user-assisted remote malicious users to execute arbitrary code via (1) a crafted stream in a .pdf file, related to "symWidths"; or (2) a crafted data stream in a .pdf file, related to "bitmaps."
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
research in motion limited blackberry enterprise server 4.1.3 |
||
research in motion limited blackberry unite 1.0.2 |
||
research in motion limited blackberry enterprise server 4.1.5 |
||
research in motion limited blackberry enterprise server 4.1.6 |
||
research in motion limited blackberry professional software 4.1.4 |
||
research in motion limited blackberry unite 1.0 |
||
research in motion limited blackberry enterprise server 4.1.4 |
||
research in motion limited blackberry unite 1.0.1 |
||
research in motion limited blackberry unite |