Another BlackBerry PDF vulnerability
Research In Motion have published an advisory saying they have identified another vulnerability in the PDF distiller of the BlackBerry Attachment service. This new vulnerability is in addition to previous issues with the PDF distiller service.
According to US-CERT, the issue is related to VU196617, which involves the open source Xpdf and poppler applications and their handling of JBIG2 data. In the BlackBerry case, the vulnerability exposes the system that hosts the BlackBerry Attachment Service and can allow arbitrary code to be executed on that system when the service is presented with a manipulated PDF file. The issue affects BlackBerry Enterprise Software versions 4.1.3 to 4.1.6 and BlackBerry Professional Software version 4.1.4.
RIM have released updates to the applications, but advise in the interim to disable PDF file processing in the BlackBerry server.
- Vulnerabilities in the PDF distiller of the BlackBerry Attachment Service for the BlackBerry Enterprise Server, security advisory from BlackBerry.
- Xpdf and poppler contain multiple vulnerabilities in the processing of JBIG2 data, US-CERT report