First published: Thu Jul 30 2009(Updated: )
Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 4.1.6 and BlackBerry Professional Software 4.1.4 allow user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .pdf file attachment, a different vulnerability than CVE-2008-3246 and CVE-2009-0219.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry Enterprise Server | =4.1 | |
BlackBerry Enterprise Server | =4.1-sp2 | |
BlackBerry Enterprise Server | =4.1-sp2 | |
BlackBerry Enterprise Server | =4.1-sp3 | |
BlackBerry Enterprise Server | =4.1.3 | |
BlackBerry Enterprise Server | =4.1.4 | |
BlackBerry Enterprise Server | =4.1.5 | |
BlackBerry Enterprise Server | =4.1.6 | |
BlackBerry Enterprise Server | =4.1.6-mr4 | |
Blackberry Professional Software | =4.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2646 is categorized as a denial of service vulnerability impacting specific BlackBerry Enterprise Server and BlackBerry Professional Software versions.
To fix CVE-2009-2646, users should upgrade to the latest version of BlackBerry Enterprise Server or BlackBerry Professional Software where the vulnerabilities are addressed.
The affected versions include BlackBerry Enterprise Server 4.1.3 through 4.1.6 and BlackBerry Professional Software 4.1.4.
Yes, CVE-2009-2646 can be exploited by remote attackers, but it requires user assistance.
CVE-2009-2646 allows user-assisted remote attackers to cause a denial of service condition.