Vulnerability CVE-2009-0176


Published: 2009-01-20   Modified: 2012-02-13

Description:
Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to "symWidths"; or (2) a crafted data stream in a .pdf file, related to "bitmaps."

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Research in motion limited -> Blackberry enterprise server 
Research in motion limited -> Blackberry professional software 
Research in motion limited -> Blackberry unite 

 References:
http://www.securityfocus.com/bid/33224
http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17119
http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17118
http://secunia.com/advisories/33534
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=765
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=764

Copyright 2024, cxsecurity.com

 

Back to Top