CVE-2009-0176
Last modified
CVE-2009-0176 is a vulnerability of currently unknown severity. Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to "symWidths"; or (2) a crafted data stream in a .pdf file, related to "bitmaps.". EPSS estimates a 5.55% chance of exploitation in the next 30 days.
Description
Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to "symWidths"; or (2) a crafted data stream in a .pdf file, related to "bitmaps."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Research In Motion Limited | Blackberry Enterprise Server | 4.1.3 |
| Research In Motion Limited | Blackberry Enterprise Server | 4.1.4 |
| Research In Motion Limited | Blackberry Enterprise Server | 4.1.5 |
| Research In Motion Limited | Blackberry Enterprise Server | 4.1.6 |
| Research In Motion Limited | Blackberry Professional Software | 4.1.4 |
| Research In Motion Limited | Blackberry Unite | <= 1.0.3 |
| Research In Motion Limited | Blackberry Unite | 1.0 |
| Research In Motion Limited | Blackberry Unite | 1.0.1 |
| Research In Motion Limited | Blackberry Unite | 1.0.2 |
References
- http://secunia.com/advisories/33534Vendor Advisory
- http://secunia.com/advisories/33534Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-0176?
How severe is CVE-2009-0176?
How do I fix CVE-2009-0176?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-0170Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1…
- CVE-2009-0171The Sun SPARC Enterprise M4000 and M5000 Server, within a ce…
- CVE-2009-0172Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 bef…
- CVE-2009-0173Unspecified vulnerability in the server in IBM DB2 8 before …
- CVE-2009-0174Stack-based buffer overflow in VUPlayer 2.49 allows remote a…
- CVE-2009-0175Heap-based buffer overflow in Heathco Software MP3 TrackMake…
- CVE-2009-0177vmwarebase.dll, as used in the vmware-authd service (aka vmw…
- CVE-2009-0178Unspecified vulnerability in IBM Hardware Management Console…
- CVE-2009-0179libmikmod 3.1.11 through 3.2.0, as used by MikMod and possib…
- CVE-2009-0180Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc…
- CVE-2009-0181Buffer overflow in VUPlayer allows user-assisted attackers t…
- CVE-2009-0182Buffer overflow in VUPlayer 2.49 and earlier allows user-ass…8.8
Are you affected by CVE-2009-0176?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
