RIM patches another BlackBerry Enterprise Server PDF Flaw

BlackBerry-maker Research In Motion (RIM) has issued a security fix to address yet another flaw in its BlackBerry Enterprise Server's (BES) BlackBerry Attachment Service, which processes message attachments for viewing on BlackBerry devices.

Share

BlackBerry-maker Research In Motion (RIM) has issued a security fix to address yet another flaw in its BlackBerry Enterprise Server's (BES) BlackBerry Attachment Service, which processes message attachments for viewing on BlackBerry devices.

Problems with the BlackBerry Attachment Service have led RIM to fix multiple issues related to the BES PDF distiller component.

Flaws in the BES PDF distiller could allow attackers to distribute messages with malicious PDF files attached that, if opened via BlackBerry, could lead to device memory corruption and in turn, harmful code could be executed on corporate computers hosting the BES Blackberry Attachment Service.

This particular flaw is found in BES version 4.1 Service Pack 3 (4.1.3) through to 5.0 and BlackBerry Professional Software 4.1 Service Pack 4 (4.1.4). The vulnerability is critical with a Common Vulnerability Scoring System (CVSS) rating of 9.3 out of 10, according to RIM.

If you or your organisation employs affected BES software click here to download an interim fix. If you use affected BlackBerry Professional Software go here.

Visit RIM's website for more details on the vulnerability, as well as potential workarounds to disable PDF viewing on enterprise BlackBerrys.

"Recommended For You"

RIM co-CEO Lazaridis on the iPhone, mobile device management BlackBerry bug forces update recall