First published: Tue Jul 28 2009(Updated: )
Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 5.0 and BlackBerry Professional Software 4.1.4 allow user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .pdf file attachment, a different vulnerability than CVE-2008-3246 and CVE-2009-0219.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry Enterprise Server | =4.1.3 | |
BlackBerry Enterprise Server | =4.1.4 | |
BlackBerry Enterprise Server | =4.1.5 | |
BlackBerry Enterprise Server | =4.1.6 | |
BlackBerry Enterprise Server | =4.1.6-mr4 | |
BlackBerry Enterprise Server | =5.0 | |
Blackberry Professional Software | =4.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2643 is classified as a denial of service vulnerability in certain versions of BlackBerry Enterprise Server and BlackBerry Professional Software.
To mitigate CVE-2009-2643, it is recommended to upgrade to the latest fixed version of BlackBerry software.
CVE-2009-2643 affects BlackBerry Enterprise Server versions 4.1.3 through 5.0 and BlackBerry Professional Software version 4.1.4.
CVE-2009-2643 allows user-assisted remote attackers to cause a denial of service on the affected systems.
There are no official workarounds for CVE-2009-2643; the best approach is to apply the relevant software updates.