Vulnerability Name: | CVE-2009-2643 (CCN-50755) | ||||||||
Assigned: | 2009-05-26 | ||||||||
Published: | 2009-05-26 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 5.0 and BlackBerry Professional Software 4.1.4 allow user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .pdf file attachment, a different vulnerability than CVE-2008-3246 and CVE-2009-0219. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-2643 Source: CCN Type: SA35254 BlackBerry Products PDF Distiller Unspecified Vulnerabilities Source: SECUNIA Type: Vendor Advisory 35254 Source: CCN Type: SECTRACK ID: 1022295 BlackBerry Enterprise Server Bug in PDF Distiller Lets Remote Users Execute Arbitrary Code Source: CONFIRM Type: Patch, Vendor Advisory http://www.blackberry.com/btsc/KB18327 Source: CCN Type: BlackBerry Security Advisory KB18327 Vulnerabilities in the PDF distiller of the BlackBerry Attachment Service for the BlackBerry Enterprise Server Source: OSVDB Type: UNKNOWN 54767 Source: CCN Type: OSVDB ID: 54767 BlackBerry Multiple Products PDF Distiller Multiple Unspecified Issues Source: BID Type: UNKNOWN 35102 Source: CCN Type: BID-35102 BlackBerry Attachment Service PDF Distiller Multiple Unspecified Security Vulnerabilities Source: SECTRACK Type: UNKNOWN 1022295 Source: VUPEN Type: Patch, Vendor Advisory ADV-2009-1429 Source: XF Type: UNKNOWN blackberry-pdf-code-execution(50755) Source: XF Type: UNKNOWN blackberry-pdf-code-execution(50755) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |