Vulnerability Name: | CVE-2010-2604 (CCN-64621) | ||||||||
Assigned: | 2010-07-01 | ||||||||
Published: | 2011-01-11 | ||||||||
Updated: | 2017-08-17 | ||||||||
Summary: | Multiple buffer overflows in the PDF Distiller in the BlackBerry Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server 4.1.3 through 5.0.2, and Enterprise Server Express 5.0.1 and 5.0.2, allow remote attackers to execute arbitrary code via a crafted PDF file. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-2604 Source: OSVDB Type: UNKNOWN 70393 Source: CCN Type: SA42882 BlackBerry Enterprise Server PDF Distiller Buffer Overflow Vulnerability Source: SECUNIA Type: Vendor Advisory 42882 Source: CCN Type: SECTRACK ID: 1024953 BlackBerry Enterprise Server Buffer Overflow in Attachment Service PDF Distiller Lets Remote Users Execute Arbitrary Code Source: CCN Type: Blackberry Security Advisory KB25382 Vulnerability in the PDF distiller of the BlackBerry Attachment Service for the BlackBerry Enterprise Server Source: CONFIRM Type: Vendor Advisory http://www.blackberry.com/btsc/KB25382 Source: CCN Type: OSVDB ID: 70393 BlackBerry Enterprise Server PDF Distiller Unspecified Overflow (2010-2604) Source: BID Type: UNKNOWN 45753 Source: CCN Type: BID-45753 BlackBerry Attachment Service PDF Distiller (CVE-2010-2604) Remote Buffer Overflow Vulnerability Source: SECTRACK Type: UNKNOWN 1024953 Source: VUPEN Type: Vendor Advisory ADV-2011-0081 Source: XF Type: UNKNOWN blackberry-pdf-distiller-bo(64621) Source: XF Type: UNKNOWN blackberry-pdf-distiller-bo(64621) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |