CVE-2009-4778: Critical severity RIM BlackBerry Enterprise Server vulnerability
Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 4.1.7 and 5.0.0, and BlackBerry Professional Software 4.1.4, allow user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .pdf file attachment, a different vulnerability than CVE-2008-3246, CVE-2009-0176, CVE-2009-0219, CVE-2009-2643, and CVE-2009-2646.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4778?
CVE-2009-4778 has a severity rating that indicates it could lead to denial of service due to vulnerabilities in the PDF distiller.
Which versions of BlackBerry Enterprise Server are affected by CVE-2009-4778?
CVE-2009-4778 affects BlackBerry Enterprise Server versions 4.1.3 to 4.1.7 and 5.0.0, as well as BlackBerry Professional Software 4.1.4.
How do I fix CVE-2009-4778?
To mitigate CVE-2009-4778, you should upgrade to a patched version of BlackBerry Enterprise Server or BlackBerry Professional Software.
Can CVE-2009-4778 be exploited remotely?
Yes, CVE-2009-4778 can allow user-assisted remote attackers to exploit the vulnerabilities.
What are the consequences of CVE-2009-4778 exploitation?
Exploitation of CVE-2009-4778 can result in a denial of service affecting the BlackBerry Enterprise Server and related services.