CVE-2009-2646: Critical severity blackberry enterprise server vulnerability
Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 4.1.6 and BlackBerry Professional Software 4.1.4 allow user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .pdf file attachment, a different vulnerability than CVE-2008-3246 and CVE-2009-0219.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2646?
CVE-2009-2646 is categorized as a denial of service vulnerability impacting specific BlackBerry Enterprise Server and BlackBerry Professional Software versions.
How do I fix CVE-2009-2646?
To fix CVE-2009-2646, users should upgrade to the latest version of BlackBerry Enterprise Server or BlackBerry Professional Software where the vulnerabilities are addressed.
What versions are affected by CVE-2009-2646?
The affected versions include BlackBerry Enterprise Server 4.1.3 through 4.1.6 and BlackBerry Professional Software 4.1.4.
Can CVE-2009-2646 be exploited remotely?
Yes, CVE-2009-2646 can be exploited by remote attackers, but it requires user assistance.
What does CVE-2009-2646 allow attackers to do?
CVE-2009-2646 allows user-assisted remote attackers to cause a denial of service condition.