PT-2008-4662 · Blackberry · Blackberry Enterprise Server+2
Publicado
2008-07-21
·
Atualizado
2017-08-08
·
CVE-2008-3246
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
BlackBerry Unite! versions 1.0.1 through 1.0.1 before bundle 36
BlackBerry Enterprise Server versions 4.1.3 through 4.1.5
Description:
The issue allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file attachment. This is related to an unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service.
Recommendations:
For BlackBerry Unite! version 1.0.1 before bundle 36, update to a version that includes bundle 36 or later.
For BlackBerry Enterprise Server versions 4.1.3 through 4.1.5, update to a version later than 4.1.5.
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Blackberry Attachment Service
Blackberry Enterprise Server
Blackberry Unite!