Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

RIM fixes critical BlackBerry Enterprise Server bug

Research in Motion patched a critical bug in its BlackBerry Enterprise Server that could have allowed hackers to break into company networks


Research in Motion patched a critical bug in its BES (BlackBerry Enterprise Server) Friday to stymie hackers hoping to break into company networks by tricking users of the popular smartphone into opening rigged PDFs.

The fix, which was delivered in several separate updates to BES, addressed a security vulnerability in the PDF distiller component of the BlackBerry Attachment Service, which runs on the BES. RIM first disclosed the flaw last week, but the bug gained attention Wednesday when the U.S. Computer Emergency Readiness Team (US-CERT), part of the Department of Homeland Security, posted an alert.

[ Learn how to secure your systems with Roger Grimes' Security Adviser blog and newsletter, both from InfoWorld. ]

Attackers could exploit the vulnerability by getting BlackBerry users to open malicious PDF files attached to e-mail messages. Successful exploits would compromise servers running BES, not individual BlackBerry devices, RIM said in security advisories first published July 10.

A RIM spokeswoman said Friday that the company had received no reports of attacks and that updates were now available for BES.

Enterprise administrators can update to BES version 4.1 Service Pack 6 (4.1.6) for Microsoft Exchange and IBM Lotus Domino, RIM said in a revised advisory. An update to BES for Novell GroupWise pegged as 4.1.4 also patches the problem.

Administrators running editions of BES older then versions 4.1.6, or 4.1.4 for GroupWise, can instead apply one of several interim security updates posted on RIM's download site.

Previously, RIM had updated the BlackBerry Unite software that users run on their smartphones to patch the problem on the client side.


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





Best Practices for Successful SOA Governance
It's widely accepted that SOA will fail to achieve the benefits it promises without a successful SOA governance strategy. What makes up a successful SOA governance strategy though? Find out some proven best practices around SOA governance that you can apply within your organization to get you on the path to success. Sponsored by Oracle

»  Click here to view this Webcast
  Planning For A Disaster
This new, comprehensive Solutions Guide is your one stop source for Disaster Recovery. In it you'll learn how to reduce the likelihood of a disaster and to create a rock solid business continuity plan should you face a disaster situation. Sponsored by Equallogic

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 09/04/2008

Sony recalls 73,000 laptops, Google to rework Chrome license after users...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist