Monday | 8 September, 2008
Computerworld
RIM warns BlackBerry admins of critical unpatched PDF bug
Company posts workaround instructions for enterprise administrators.
Gregg Keizer 18/07/2008 08:15:00

Computerworld Buyer's Guide - Vendors Matched to this Article
Related Features
  • +

    Your World. . . Hacked 02/10/2007 10:51:23

    As your business becomes more collaborative and global, the risks to your company’s trade secrets rise proportionally. Fortunately, there are new strategies to protect the data that allows you to compete
    The call to Bob Bailey, an IT executive with a major US government contractor, came on an otherwise ordinary day in October 2003. "Why are you attacking us?" demanded the caller, an IT leader with a Silicon Valley manufacturer. He wanted to know why Bailey's company had launched a denial-of-service attack against his network
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.

Newsletter Subscription

Sign up for our Computerworld newsletters!
Computerworld's twice-daily news service keeps you in touch with the latest, most important headlines from Australia and around the world.
Keep up with the latest virtualisation technologies, products, news and features.
RSS Feeds

Research in Motion has warned users and corporate administrators of a critical vulnerability in a component of its BlackBerry Enterprise Server that could be used to hack their company's computers.

The US Computer Emergency Readiness Team (US-CERT), part of the Department of Homeland Security, also posted an alert Wednesday after RIM issued two security advisories.

A patch is not available, but RIM said the problem had been "escalated internally to our development team."

A bug in the PDF distiller component of the BlackBerry Attachment Service, which runs on the BlackBerry Enterprise Server (BES), affects how the popular Adobe document format is processed on the server, said RIM in one of the advisories.

The server running BES, not individual BlackBerry devices, is at risk, although an attack would involve a BlackBerry.

Malicious PDFs attached to e-mail messages could "cause arbitrary code to execute on the computer that the BlackBerry Attachment Service runs on," the RIM warning said. "If a BlackBerry smart phone user on a BlackBerry Enterprise Server opens and views the specially crafted PDF file attachment on the BlackBerry smart phone, the arbitrary code execution could compromise the computer."

RIM posted workaround instructions for enterprise administrators that would prevent an attack by blocking PDF processing on a BES system.

A companion RIM security advisory urged BlackBerry users to upgrade to version 1.0 Service Pack 1 (1.0.1) bundle 36 or later of the BlackBerry Unite software.

Computerworld Buyer's Guide - Vendors Matched to this Article
More about BlackBerry, Adobe, Motion, RIM, CERT
Market Place

Computerworld Member Login


 

Prioritizing Services with IT Service Management (ITSM)

Computerworld Live Webinar
Wednesday 20th, August 2008
11:00am EST (Sydney, Australia)

To be repeated on:

Thursday 4th, September 2008
11:00am EST (Sydney Australia)

Sign up and receive a free copy of The Forrester WaveTM Service Desk Management Tools, Q2 2008 at the conclusion of the Webinar.

Attend and discover:

  • How to deliver value to your business through ITSM
  • Best practice ITSM implementation
  • Why emphasis is changing from optimizing IT management processes to better servicing customers and demonstrating real dollar value
  • If service-oriented ITSM is best for your business
Whitepaper

Market Trends: Multienterprise/B2B Infrastructure Market | Worldwide | 2008

Garner says global 2000 companies will double their multi-enterprise traffic in the next 5 years. Discover the key technology and business drivers that will enable this.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links