We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message
79,994 News Articles

BlackBerry vulnerability alert

RIM warns admins of critical unpatched PDF bug

Research in Motion (RIM) has warned users and corporate administrators of a critical vulnerability in a component of its BlackBerry Enterprise Server that could be used to hack their company's computers.

The US Computer Emergency Readiness Team (US-CERT), part of the Department of Homeland Security, also posted an alert Wednesday after RIM issued two security advisories.

A patch is not available, but RIM said the problem had been "escalated internally to our development team."

A bug in the PDF distiller component of the BlackBerry Attachment Service, which runs on the BlackBerry Enterprise Server (BES), affects how the popular Adobe document format is processed on the server, said RIM in one of the advisories.

The server running BES, not individual BlackBerry devices, is at risk, although an attack would involve a BlackBerry.

Malicious PDFs attached to email messages could "cause arbitrary code to execute on the computer that the BlackBerry Attachment Service runs on," the RIM warning said.

"If a BlackBerry smart phone user on a BlackBerry Enterprise Server opens and views the specially crafted PDF file attachment on the BlackBerry smart phone, the arbitrary code execution could compromise the computer."

RIM posted workaround instructions for enterprise administrators that would prevent an attack by blocking PDF processing on a BES system.

A companion RIM security advisory urged BlackBerry users to upgrade to version 1.0 Service Pack 1 (1.0.1) bundle 36 or later of the BlackBerry Unite software.


IDG UK Sites

45 Best Android games: top Android games for your smartphone or tablet in 2014 (24 are free!)

IDG UK Sites

How Apple, Adobe, Microsoft and others have let us down over UltraHD and hiDPI screens

IDG UK Sites

Do you have the X-Factor too? Mix Off app puts fans in the frame

IDG UK Sites

iPad Pro release date, rumours and leaked images - 12.9 screen 'coming in 2015'