Research in Motion (RIM) issued an advisory with patches for
multiple flaws in the PDF distiller service and warned and an attacker
could exploit the issues by simply e-mailing a booby-trapped PDF file
to a BlackBerry user.
exist in the PDF distiller of some released versions of the BlackBerry
Attachment Service component of the BlackBerry Enterprise Server:
vulnerabilities could enable a malicious individual to send an email
message containing a specially crafted PDF file, which when opened for
viewing on a BlackBerry smartphone that is associated with a user
account on a BlackBerry Enterprise Server, could cause memory
corruption and possibly lead to a Denial of Service (DoS) condition or
arbitrary code execution on the computer that hosts the BlackBerry
Attachment Service component of that BlackBerry Enterprise Server.
Affected versions include the BlackBerry Enterprise Server 5.0.0
running on Microsoft Windows version 2003 or 2008, BlackBerry
Enterprise Server 5.0.0 running on Microsoft Windows 2000, BlackBerry
Enterprise Server software versions 4.1.3 through 4.1.7, and BlackBerry
Professional Software 4.1.4.
Instructions on applying the patches are available in this RIM advisory.