-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
                         AUSCERT Security Bulletin

                               ASB-2010.0226
          Vulnerabilities in the PDF distiller of the BlackBerry
          Attachment Service for the BlackBerry Enterprise Server
                              14 October 2010

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:              BlackBerry Enterprise Server
Operating System:     Windows
Impact/Access:        Execute Arbitrary Code/Commands -- Remote with User Interaction
                      Denial of Service               -- Remote with User Interaction
Resolution:           Patch/Upgrade
CVE Names:            CVE-2010-2601  
Member content until: Saturday, November 13 2010

OVERVIEW

        A vulnerability has been found in the PDF distiller of the BlackBerry
        Attachment Service for the BlackBerry Enterprise Server which may lead
        to the execution of arbitrary code or a denial of service.


IMPACT

        The vendor has provided the following information regarding this
        vulnerability:
        
        "The vulnerability could allow a malicious individual to cause buffer
        overflow errors, leading to a Denial of Service (DoS) condition or
        possibly arbitrary code execution on the computer that the
        BlackBerry Attachment Service runs on.
        
        Successful exploitation of this issue requires a malicious
        individual to persuade a BlackBerry smartphone user to open a
        specially crafted PDF file on a BlackBerry smartphone that is
        associated with a user account on a BlackBerry Enterprise Server. The
        PDF file may be attached to an email message, or the BlackBerry
        smartphone user may retrieve it from a web site using the Get Link
        menu item on the BlackBerry smartphone." [1]


MITIGATION

        Updates and interim fixes are available for following versions:
        
        * BlackBerry Enterprise Server Express version 5.0.2  Microsoft
          Exchange [2]
        
        * BlackBerry Enterprise Server version 5.0.0  Microsoft Exchange
          and IBM Lotus Domino [2]
        
        * BlackBerry Enterprise Server version 5.0.1  Microsoft Exchange,
          IBM Lotus Domino, and Novell GroupWise [2]
        
        * BlackBerry Enterprise Server version 5.0.2  Microsoft Exchange
          and IBM Lotus Domino [2]
        
        * BlackBerry Enterprise Server version 4.1.7  Microsoft Exchange and
          IBM Lotus Domino [2]
        
        * BlackBerry Enterprise Server version 4.1.7  Novell GroupWise [2]
        
        * BlackBerry Enterprise Server version 4.1.6  Microsoft Exchange,
          IBM Lotus Domino, and Novell GroupWise [2]
        
        The vendor has also provided workarounds to prevent the BlackBerry
        Attachment Service from processing PDF files in a BlackBerry 
        Enterprise Server environment . [1]


REFERENCES

        [1] Vulnerability in the PDF distiller of the BlackBerry Attachment
            Service for the BlackBerry Enterprise Server
            http://blackberry.com/btsc/KB24547

        [2] Software Download for BlackBerry Enterprise Server
            http://www.blackberry.com/go/serverdownloads

AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours 
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iD8DBQFMtlCi/iFOrG6YcBERAvcdAJ95EGjH/vRbKJuOzoKu56lzgCDjGACfawBb
jJu4rK2ivcgUCV5AvJZ9/uw=
=XD/S
-----END PGP SIGNATURE-----