CVE-2010-2601

Multiple buffer overflows in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.7 and earlier and 5.0.0 through 5.0.2, and BlackBerry Professional Software 4.1.4 and earlier, allow user-assisted remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted PDF document.
References
Link Resource
http://blackberry.com/btsc/KB24547 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rim:blackberry_enterprise_server:*:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:2.2:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:3.6:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:3.6.1:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:4.0:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:4.0:sp3:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:4.1:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:4.1.3:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:4.1.4:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:4.1.5:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:4.1.6:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:4.1.6:mr4:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_enterprise_server:5.0.2:*:*:*:*:*:*:*
cpe:2.3:a:rim:blackberry_professional_software:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2010-10-14 18:00

Updated : 2024-02-28 11:41


NVD link : CVE-2010-2601

Mitre link : CVE-2010-2601

CVE.ORG link : CVE-2010-2601


JSON object : View

Products Affected

rim

  • blackberry_professional_software
  • blackberry_enterprise_server
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer