#Blackberry #BES #Exchange
Source: http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB24547
Product(s) Affected:
- BlackBerry® Enterprise Server Express
- BlackBerry® Enterprise Server for IBM® Lotus® Domino®
- BlackBerry® Enterprise Server for Microsoft® Exchange
- BlackBerry® Enterprise Server for Novell® GroupWise®
The vulnerability could allow a malicious individual to cause buffer overflow errors, leading to a Denial of Service (DoS) condition or possibly arbitrary code execution on the computer that the BlackBerry Attachment Service runs on.
Successful exploitation of this issue requires a malicious individual to persuade a BlackBerry smartphone user to open a specially crafted PDF file on a BlackBerry smartphone that is associated with a user account on a BlackBerry Enterprise Server. The PDF file may be attached to an email message, or the BlackBerry smartphone user may retrieve it from a web site using the Get Link menu item on the BlackBerry smartphone.