PT-2008-4662 · Blackberry · Blackberry Enterprise Server+2

Publicado

2008-07-21

·

Atualizado

2017-08-08

·

CVE-2008-3246

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: BlackBerry Unite! versions 1.0.1 through 1.0.1 before bundle 36 BlackBerry Enterprise Server versions 4.1.3 through 4.1.5
Description: The issue allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file attachment. This is related to an unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service.
Recommendations: For BlackBerry Unite! version 1.0.1 before bundle 36, update to a version that includes bundle 36 or later. For BlackBerry Enterprise Server versions 4.1.3 through 4.1.5, update to a version later than 4.1.5.

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3246

Produtos afetados

Blackberry Attachment Service
Blackberry Enterprise Server
Blackberry Unite!