Mobile Advisor

RIM patches BlackBerry PDF vulnerability
IT departments should prevent attachment service from processing any PDF files

Research in Motion (RIM) has issued a new security patch for BlackBerry Enterprise Server to fix vulnerabilities in its PDF distiller program.

The patch was issued on a BlackBerry forum last week and was billed as a fix for any customers that use BlackBerry Enterprise Server (BES) versions 4.1 through 5.0. RIM said that there were "multiple security vulnerabilities" that existed in some versions of the enterprise servers' PDF distiller that were released as part of the BlackBerry Attachment Service.

The vulnerabilities could allow hackers to send users e-mails containing a "specifically crafted PDF file" that could cause memory corruption and "possibly lead to arbitrary code execution" of the computer hosting the attachment service.

While companies take time to test the new patch on their systems, RIM recommends that IT departments prevent the attachment service from processing any PDF files that come through the BES environment (instructions for disabling PDF downloads can be found here).

RIM also says that companies could install the attachment service onto a remote computer and place it in its own remote network segment to stop the spread of malicious PDF files throughout the network.

More about BlackBerry, Motion, RIM
Recommend this article?
Yes0 votes
No0 votes

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Enter the fully qualified URL, eg. http://www.example.com/
Users posting comments agree to the PC World comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Syndicate content Syndicate content Syndicate content Syndicate content Syndicate content Syndicate content
 
Gift Guide
MWave
Samsung

CXO Latest

LED Advisor
 

Colour your world with Samsung

A chance to win with every
Samsung Consumable purchase*