CVE-2009-0176
Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to "symWidths"; or (2) a crafted data stream in a .pdf file, related to "bitmaps."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 5.55% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- research in motion limited/blackberry enterprise server · research in motion limited/blackberry professional software · research in motion limited/blackberry unite
- Source
- cve@mitre.org
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=764
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=765
- http://secunia.com/advisories/33534Vendor Advisory
- http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17118Vendor Advisory
- http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17119Vendor Advisory
- http://www.securityfocus.com/bid/33224
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=764
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=765
- http://secunia.com/advisories/33534Vendor Advisory
- http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17118Vendor Advisory
- http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB17119Vendor Advisory
- http://www.securityfocus.com/bid/33224
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.