The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted data stream in a .pdf file.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-01-20 17:30
Updated : 2009-02-04 22:53
NVD link : CVE-2009-0219
Mitre link : CVE-2009-0219
JSON object : View
CWE
CWE-399
Resource Management Errors
Products Affected
research_in_motion_limited
- blackberry_unite
- blackberry_enterprise_server
- blackberry_professional_software