BlackBerry Forums Support Community
              

Closed Thread
 
Thread Tools
Old 07-17-2008, 11:13 AM   #21
Canfor
New Member
 
Join Date: Feb 2008
Model: 9530
PIN: N/A
Carrier: Telus
Posts: 2
Default

Please Login to Remove!

Does anybody know if this vulderability affects BES Version 4.0 Service Pack 5 ? The article states only versions 4.1.3 to 4.1.5, but I just wanted to be safe.
Offline  
Old 07-17-2008, 01:01 PM   #22
JavaJunkee
Thumbs Must Hurt
 
JavaJunkee's Avatar
 
Join Date: Jan 2007
Location: Seattle, WA
Model: 9780
Carrier: T-Mobile
Posts: 156
Default

I disabled PDF processing on my production BES (4.1.4) and my test BES (4.1.5). It's just not worth the risk. All it takes, is 'one' malformed PDF file.
Offline  
Old 07-17-2008, 01:36 PM   #23
SoUnCool
Talking BlackBerry Encyclopedia
 
Join Date: Feb 2007
Location: Toronto
Model: 9800
Carrier: Rogers
Posts: 319
Default

did any one have a luck finding what that "specially crafted" pdf file may look or feel like?
Offline  
Old 07-17-2008, 01:50 PM   #24
DarthBBerry
Wireless Sith Lord
 
DarthBBerry's Avatar
 
Join Date: Jan 2007
Location: Online
Model: iOS 6
Carrier: Verizon x2
Posts: 1,458
Default

Quote:
Originally Posted by SoUnCool View Post
did any one have a luck finding what that "specially crafted" pdf file may look or feel like?
Not taking the chance. Why look for trouble when it can be prevented in the first place?
__________________
DarthBBerry
6-Time BlackBerry World Champion (2007-2012)
BlackBerry® Certified Support Specialist v5.0
BlackBerry® Certified System Administrator v5.0
Offline  
Old 07-17-2008, 01:58 PM   #25
rsk
Thumbs Must Hurt
 
Join Date: Jan 2007
Model: 9630
Carrier: Sprint
Posts: 134
Default

I'm just about to put the block in. Not worth the risk..
Offline  
Old 07-17-2008, 02:11 PM   #26
mitchelrl
Thumbs Must Hurt
 
mitchelrl's Avatar
 
Join Date: Sep 2007
Model: 8900
PIN: N/A
Carrier: T-Mobile
Posts: 67
Default

We're recommending this temporary workaround to all of our clients as of now...It's way too risky
__________________
Mitchel Lewis - (Sys, BES, Exchange, SAN, Network) Admin
Current: 8900 on .168
Exchange 2007 and Blackberry Enterprise Server
Offline  
Old 07-17-2008, 02:45 PM   #27
SoUnCool
Talking BlackBerry Encyclopedia
 
Join Date: Feb 2007
Location: Toronto
Model: 9800
Carrier: Rogers
Posts: 319
Default

Quote:
Originally Posted by DarthBBerry View Post
Not taking the chance. Why look for trouble when it can be prevented in the first place?
We have put the work around in place, but just curious to see if our antivirus and antispam systems can capture such pdf file at entry level before even touching exchange !!!
Offline  
Old 07-17-2008, 07:22 PM   #28
twinkiefan
Knows Where the Search Button Is
 
Join Date: Aug 2006
Location: North of Mizzou
Model: 9700
OS: 5.0.0.330
Carrier: T-Mobile
Posts: 48
Default

we're putting the workaround in place, too. don't really think it's necessary in our case due to some additional safeguards we have in place, but like someone else said...why take the chance? If many of our 4000 users complain and a fix from RIM isn't forthcoming, we'll perhaps revisit the decision.
__________________
BES 4.1.7, Exchange 2007 SP2, SQL 2005, Windows 2003 Server on an ESX VMWare. T-Mobile = our preferred carrier.
Offline  
Old 07-17-2008, 08:13 PM   #29
exchangemymail
Thumbs Must Hurt
 
exchangemymail's Avatar
 
Join Date: Jul 2005
Location: New York
Model: 8830
Carrier: AT&T
Posts: 178
Default

We have also put this into effect. Not worth the risk.
__________________
Microsoft Gold Certified Partner
BlackBerry Aliance Member
Sales: 516-484-0077
Support: 516-484-0077
Exchangemymail.com
GBESX.com
Offline  
Old 07-17-2008, 08:21 PM   #30
ObliteRon
Knows Where the Search Button Is
 
Join Date: Oct 2007
Location: Sacramento, CA
Model: Storm
OS: 5.0.0.328
Carrier: Verizon Wireless
Posts: 32
Default

Workaround was implemented tonight.

BES 4.1.6 was just released, which addresses the vulnerability. (Advisory has been updated to reflect that.) Downloading now...
Offline  
Old 07-17-2008, 10:15 PM   #31
jibi
BlackBerry God
 
jibi's Avatar
 
Join Date: Oct 2004
Location: Jibi's Secret Place
Model: 8900
OS: 4.6.1.174
Carrier: AT&T
Posts: 11,310
Default

The Quick Fixes are also available for 4.1 SP3, SP4 and SP5.

BES 4.1 SP5 does not require the MR1 patch, although it is recommended.
BES 4.1 SP4 requires MR6 to be installed.
BES 4.1 SP3 requires HF2 to be installed.

The Quick Fix is a zip file with the updated files. There are manual commands for un-registering and re-registering some DLL files. The BlackBerry Attachment Service and BlackBerry Dispatcher will need to be stopped during this change and restarted afterwards.
__________________
In the beginning the Universe was created. This has made a lot of people very angry and is widely regarded as a bad move.
Offline  
Old 07-17-2008, 11:17 PM   #32
ObliteRon
Knows Where the Search Button Is
 
Join Date: Oct 2007
Location: Sacramento, CA
Model: Storm
OS: 5.0.0.328
Carrier: Verizon Wireless
Posts: 32
Default

Thanks for the heads-up, jibi. Workaround backed out, and the "interim security software update" has been applied.
Offline  
Old 07-18-2008, 04:01 AM   #33
Rubbery
New Member
 
Join Date: Jan 2008
Model: Pearl
PIN: N/A
Carrier: o2
Posts: 6
Question

My BES is reported as 4.1.4.15

Do i need the patch and if so does it need anything else before i put it on. Not sure what MR6 means?

Sorry - could someone please clarify if you have a minute!


Many thanks

Jon
Offline  
Old 07-18-2008, 04:10 AM   #34
Noonien
Thumbs Must Hurt
 
Join Date: Sep 2007
Model: ALL
PIN: N/A
Carrier: Different
Posts: 151
Default

Cant find the Hotfix for 4.1.3 and 4.1.4 only the SP6 .
Can someone help with a link ?
Offline  
Old 07-18-2008, 04:13 AM   #35
Noonien
Thumbs Must Hurt
 
Join Date: Sep 2007
Model: ALL
PIN: N/A
Carrier: Different
Posts: 151
Default

Quote:
Originally Posted by jibi View Post
The Quick Fixes are also available for 4.1 SP3, SP4 and SP5.

BES 4.1 SP5 does not require the MR1 patch, although it is recommended.
BES 4.1 SP4 requires MR6 to be installed.
BES 4.1 SP3 requires HF2 to be installed.

The Quick Fix is a zip file with the updated files. There are manual commands for un-registering and re-registering some DLL files. The BlackBerry Attachment Service and BlackBerry Dispatcher will need to be stopped during this change and restarted afterwards.
Hmm , 4.1 SP3 HF2 is nothing new , i installed that i think 6 month ago.
Does this fix the problem or is the SP6 needed ?
Offline  
Old 07-18-2008, 05:33 AM   #36
Noonien
Thumbs Must Hurt
 
Join Date: Sep 2007
Model: ALL
PIN: N/A
Carrier: Different
Posts: 151
Default

The release notes for SP6 dont even mentions that the distiller problem is fixed ....
Offline  
Old 07-18-2008, 07:56 AM   #37
JGonzalezGUS
Thumbs Must Hurt
 
Join Date: Jan 2007
Location: Tallahassee, FL USA
Model: 8830
Carrier: Verizon Wireless
Posts: 104
Default

We run 4.1.4 MR1. The vulnerability fix says MR6 is required. I see only in the Download area up to MR3 (no MR4, MR5 or MR6). Where can I find MR6?
If that is a typo and instead it should read 'MR3', can I install MR3 without first installing MR2?
Thanks for any info,
__________________
Jose
BES 4.1.6, Domino 6.5.4, remote SQL2005
Offline  
Old 07-18-2008, 08:11 AM   #38
mattk0
Thumbs Must Hurt
 
Join Date: Aug 2006
Model: 9530
Carrier: Verizon
Posts: 193
Default

So, if I install the 'quick fix'/interim update will people be able to get PDF's on their device still or does this block all PDF's?
Offline  
Old 07-18-2008, 08:14 AM   #39
greg2step
Knows Where the Search Button Is
 
Join Date: Feb 2007
Location: Maryland
Model: 8330
Carrier: VZW
Posts: 46
Default

We are currently running 4.14mr5 + the Out of Office quickfix so that OOF messages work ok on Exchange 2007 mailboxes. Will that fix work with 4.14mr6 and the .pdf fix?
Offline  
Old 07-18-2008, 08:17 AM   #40
SoUnCool
Talking BlackBerry Encyclopedia
 
Join Date: Feb 2007
Location: Toronto
Model: 9800
Carrier: Rogers
Posts: 319
Default

we are at BES 4.1 SP4 MR4
what happend to MR5 ? on RIM site there is MR6 after MR4 ???
Offline  
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


Vintage Mac Warehouse  3.5” Floppy Disk Solar Powered Calculator Company Swag picture

Vintage Mac Warehouse 3.5” Floppy Disk Solar Powered Calculator Company Swag

$51.80



Vintage V-Mac Industries Inc. Pipe Threader Vosper Drophead Threader - READ picture

Vintage V-Mac Industries Inc. Pipe Threader Vosper Drophead Threader - READ

$199.00



Vintage MAC USA 18-6 XDM Six Points 18 MM Socket 3/8

Vintage MAC USA 18-6 XDM Six Points 18 MM Socket 3/8" Drive Used Excellent Condi

$14.99



Vintage White APPLE IMAC EMC 1857 15

Vintage White APPLE IMAC EMC 1857 15" 20GB HDD Mac OSX 10.2 256MB RAM 500MHz

$85.00



Vintage UNHOLTZ-DICKIE MAC-6C Equipment - Untested As-is picture

Vintage UNHOLTZ-DICKIE MAC-6C Equipment - Untested As-is

$71.99



Vintage MAC TOOLS 18MM Combination Wrench M18CW Metric 12 point **Made in USA** picture

Vintage MAC TOOLS 18MM Combination Wrench M18CW Metric 12 point **Made in USA**

$26.50







Copyright © 2004-2016 BlackBerryForums.com.
The names RIM © and BlackBerry © are registered Trademarks of BlackBerry Inc.