The BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.0 to version 4.0 Service Pack 2 allows attackers to cause a denial of service via a malformed Portable Network Graphics (PNG) file that triggers a heap-based buffer overflow.
| Software | From | Fixed in |
|---|---|---|
| rim / blackberry_enterprise_server | 4.0_sp2 | 4.0_sp2.x |
| rim / blackberry_enterprise_server | 4.0_sp1 | 4.0_sp1.x |
| rim / blackberry_enterprise_server | 4.0 | 4.0.x |