Click here for case studies, whitepapers and other useful vendor content Newsletter Subscription
Research in Motion has warned users and corporate administrators of a critical vulnerability in a component of its BlackBerry Enterprise Server that could be used to hack their company's computers.
The US Computer Emergency Readiness Team (US-CERT), part of the Department of Homeland Security, also posted an alert Wednesday after RIM issued two security advisories.
A patch is not available, but RIM said the problem had been "escalated internally to our development team."
A bug in the PDF distiller component of the BlackBerry Attachment Service, which runs on the BlackBerry Enterprise Server (BES), affects how the popular Adobe document format is processed on the server, said RIM in one of the advisories.
The server running BES, not individual BlackBerry devices, is at risk, although an attack would involve a BlackBerry.
Malicious PDFs attached to e-mail messages could "cause arbitrary code to execute on the computer that the BlackBerry Attachment Service runs on," the RIM warning said. "If a BlackBerry smart phone user on a BlackBerry Enterprise Server opens and views the specially crafted PDF file attachment on the BlackBerry smart phone, the arbitrary code execution could compromise the computer."
RIM posted workaround instructions for enterprise administrators that would prevent an attack by blocking PDF processing on a BES system.
A companion RIM security advisory urged BlackBerry users to upgrade to version 1.0 Service Pack 1 (1.0.1) bundle 36 or later of the BlackBerry Unite software.
ARN Member Login
When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
F-Secure achieves excellent results in Internet security suite comparison 10 October, 2008 14:37:00
Lock It Up With Maxtor BlackArmour, Hardware Encrypted Storage Provides Government Grade Security For Consumers 10 October, 2008 09:04:00
M2M Connectivity announces the new Sierra Wireless MC8792V embedded module for 900 MHz 3G/HSPA networks 10 October, 2008 08:51:00
IOGEAR Gears Up in Australia 09 October, 2008 20:18:00
Symantec to Extend Online Services with Acquisition of MessageLabs 09 October, 2008 11:48:00
Bankstown Council streamlines their IT with Microsoft® Windows Server® 2008
Deciding it was time for more streamlined operations, Bankstown Council teamed up with OSS Infotech, a Microsoft Gold Certified Partner. The solution included Microsoft Windows Server, Microsoft SQL Server® and Microsoft Exchange®.









