>> BlackBerry Products PDF Distiller Remote Code Execution Vulnerability
Title : BlackBerry Products PDF Distiller Remote Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2008-2108 CVE ID : CVE-2008-3246 CWE ID : CWE-20
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-07-15
Technical Description
A vulnerability has been identified in BlackBerry Enterprise Server and BlackBerry Unite!, which could be exploited by attackers to compromise a vulnerable system. This issue is caused by an unspecified error in the PDF distiller of the BlackBerry Attachment Service when processing specially crafted PDF file attachments, which could be exploited by attackers to execute arbitrary code on a vulnerable system by tricking a user into opening a malicious PDF file.