ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

BlackBerry bitten by PDF distiller security hole

By | October 14, 2010, 9:00am PDT

Summary: A serious security flaw in the way Research in Motion’s BlackBerry Enterprise Server processes PDF files could expose businesses to remote code execution attacks

A serious security flaw in the way Research in Motion’s BlackBerry Enterprise Server processes PDF files could expose businesses to remote code execution attacks, the company warned in an advisory.

The vulnerability, discovered in the PDF distiller of the BlackBerry attachment service for the BlackBerry Enterprise Server, could allow a hacker take control of the computer that the BlackBerry Attachment Service runs on.

Here’s the gist of the problem from RIM’s advisory:follow Ryan Naraine on twitter

The vulnerability could allow a malicious individual to cause buffer overflow errors, leading to a Denial of Service (DoS) condition or possibly arbitrary code execution on the computer that the BlackBerry Attachment Service runs on.

Successful exploitation of this issue requires a malicious individual to persuade a BlackBerry smartphone user to open a specially crafted PDF file on a BlackBerry smartphone that is associated with a user account on a BlackBerry Enterprise Server. The PDF file may be attached to an email message, or the BlackBerry smartphone user may retrieve it from a web site using the Get Link menu item on the BlackBerry smartphone.

RIM recommends that BlackBerry Enterprise Server administrators to review and apply available patches or consider implementing workaround in the advisory.

Affected software include:

  • BlackBerry Enterprise Server Express version 5.0.2 for Microsoft Exchange
  • BlackBerry Enterprise Server versions 5.0.2, 5.0.1, 5.0.0, 4.1.7 and earlier for Microsoft Exchange
  • BlackBerry Enterprise Server versions 5.0.2, 5.0.1, 5.0.0, 4.1.7 and earlier for IBM Lotus Domino
  • BlackBerry Enterprise Server versions 5.0.1, 4.1.7 and earlier for Novell GroupWise
  • BlackBerry® Professional Software version 4.1.4 and earlier for Microsoft Exchange and IBM Lotus Domino

This issue does not affect BlackBerry smartphones.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?
6
Comments

Join the conversation!

Just In

RE: BlackBerry bitten by PDF distiller security hole
saieazby 25th Sep
What exactly can you feel is the distinction involving generic Propecia and also Finpecia online?
0 Votes
+ -
RE: BlackBerry bitten by PDF distiller security hole
putty.master Updated - 14th Oct 2010
This would be a problem if anybody actually opened PDFs on their Blackberry. I've tried it a few times, and no, I can't see jack s*** no matter how much zooming and scrolling I do. And that's after waiting a couple minutes for it to download. I'm yet to see a PDF I can read even a single word from using a Blackberry. Eventually I stopped trying. If an e-mail has a PDF attached, I'll wait until I get to my desktop to try and open it.
0 Votes
+ -
ROFL PDF on blackberry is a joke.
0 Votes
+ -
Essential reading for every hacker...
ulrichburke@... 14th Oct 2010
These articles must be required reading for every hacker out there. Not only do they explain where all the flaws are, they explain how to exploit them and even say what measures are being taken to patch them, so the prospective hacker will know how to craft his virus to work around them.

Wonderful stuff! I, for one, couldn't do my work without them.

Keep 'em coming!
0 Votes
+ -
Another security threat!?
Zc456 15th Oct 2010
So, when did PDF suddenly become as full of holes as Windows? :P
@Zc456: So, when did PDF suddenly become as full of holes as Windows?

Maybe there's some type of counseling you could attend?
What exactly can you feel is the distinction involving generic Propecia and also Finpecia online?

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix