CVE-2009-2643: Critical severity blackberry enterprise server vulnerability
Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 5.0 and BlackBerry Professional Software 4.1.4 allow user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .pdf file attachment, a different vulnerability than CVE-2008-3246 and CVE-2009-0219.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2643?
CVE-2009-2643 is classified as a denial of service vulnerability in certain versions of BlackBerry Enterprise Server and BlackBerry Professional Software.
How do I fix CVE-2009-2643?
To mitigate CVE-2009-2643, it is recommended to upgrade to the latest fixed version of BlackBerry software.
Which software versions are affected by CVE-2009-2643?
CVE-2009-2643 affects BlackBerry Enterprise Server versions 4.1.3 through 5.0 and BlackBerry Professional Software version 4.1.4.
What impact does CVE-2009-2643 have on users?
CVE-2009-2643 allows user-assisted remote attackers to cause a denial of service on the affected systems.
Is there a workaround for CVE-2009-2643?
There are no official workarounds for CVE-2009-2643; the best approach is to apply the relevant software updates.