VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-2601
blackberry_enterprise_server, blackberry_professional_software: Multiple buffer overflows in the PDF distiller in t...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-2601

Original

Multiple buffer overflows in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.7 and earlier and 5.0.0 through 5.0.2, and BlackBerry Professional Software 4.1.4 and earlier, allow user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted PDF document.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-10-14
Source Information Category:
Advisory, Alert
Last Updated:
2010-10-15




Affected Product Tags
cpe:/a:rim:blackberry_enterprise_server:2.2
cpe:/a:rim:blackberry_enterprise_server:3.6
cpe:/a:rim:blackberry_enterprise_server:3.6.1
cpe:/a:rim:blackberry_enterprise_server:4.0
cpe:/a:rim:blackberry_enterprise_server:4.0.3
cpe:/a:rim:blackberry_enterprise_server:4.0:sp3
cpe:/a:rim:blackberry_enterprise_server:4.1
cpe:/a:rim:blackberry_enterprise_server:4.1.3
cpe:/a:rim:blackberry_enterprise_server:4.1.4
cpe:/a:rim:blackberry_enterprise_server:4.1.5
cpe:/a:rim:blackberry_enterprise_server:4.1.6
cpe:/a:rim:blackberry_enterprise_server:4.1.6:mr4
cpe:/a:rim:blackberry_enterprise_server:4.1.7 and previous versions
cpe:/a:rim:blackberry_enterprise_server:5.0.0
cpe:/a:rim:blackberry_enterprise_server:5.0.1
cpe:/a:rim:blackberry_enterprise_server:5.0.2
cpe:/a:rim:blackberry_professional_software:4.1.4 and previous versions
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

X High [?]
Medium [?]
Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

Alternatives




References
CONFIRM http://blackberry.com/btsc/KB24547




Vulnerability Type Buffer Errors (CWE-119)





Copyright © 2010 JPCERT/CC All Rights Reserved.