RIM BlackBerry Enterprise Server (BES) 4.1.6 Upgrade Addresses Critical PDF Flaw

Research In Motion (RIM) has released an upgrade to its BlackBerry Enterprise Server (BES) software that fixes a previously disclosed vulnerability and provides new e-mail and calendaring functionality for administrators and corporate smartphone users.

By
Fri, July 18, 2008

CIOResearch In Motion (RIM) on Thursday quietly released an upgrade to its BlackBerry Enterprise Server (BES) software, BES 4.1 service pack 6 (SP6), or BES v4.1.6, for Microsoft Exchange and Lotus Domino. The update follows a security advisory issued by RIM last week regarding a critical flaw in BES versions 4.1.3 through 4.1.5 that could enable hackers to hijack users' BES infrastructure.

According to RIM, the flaw in the BES BlackBerry Attachment Service's PDF distiller component, which prepares Adobe PDF files to be opened on BlackBerry handhelds, has been fixed in BES 4.1.6.

"In regard to the precautionary security advisory issued by RIM which informed customers about a potential vulnerability in BlackBerry Enterprise Server versions 4.1.3 through 4.1.5, there were no customer reports of any actual problems relating to this vulnerability and RIM has since provided software updates that resolve the issue," according to a RIM spokesperson. "Note: The vulnerability does not exist in the newly released BlackBerry Enterprise Server 4.1.6."

In addition to fixing the flaw, which was ranked by RIM as a nine on a scale of one to 10 with 10 being the most serious, the upgrade also makes a handful of new features and functionality available to both corporate BlackBerry users and administrators.

For instance, BlackBerry users on BES 4.1.6 can now receive HTML and rich-content e-mail by default, as long as their devices are running handheld OS v4.5. (BlackBerry OS v4.5 is not yet officially available from U.S. carriers, though beta versions have been bouncing around the Web for some time and official versions are expected in the near future.) For more information on the potential effects of supporting full HTML e-mail in a corporate environment, visit the Documentation for Administrators section of RIM's site.

image of BES 4.1.6 Download Page
BES 4.1.6 Download Page


As part of BES 4.1.6, BlackBerry administrators now have new support for Microsoft Office Communications Server 2007 and IBM Lotus Sametime v8.0, as well as new naming conventions for the collaboration clients and a new BlackBerry calendar synchronization tool, among other enhancements.

BlackBerry administrators can download the upgrade from RIM's site, and additional information on BES 4.1.6 and its new functionality can be found in the software's release notes.

The last major BES upgrade, 4.1.5, was released only a few months ago in April.

FREE CIO BlackBerry Newsletter
Get better use out of your BlackBerry and keep up-to-date on the latest developments. Sign-up »
Virtualization and cloud are driving new requirements for data center network performance, VM support, automation and simplified orchestration. This paper outlines Extreme Networks® open fabric approach to high speed, low latency networks for modern data centers.
The evolution of the network to provide the intelligence needed to address user, device and application mobility is underway. In this white paper, Extreme Networks® outlines the five phases required to bring mobility into the network.
Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil society, as well as friends and family.
Whether you need to build a business case for a UC system, or are ready to select a new solution, this white paper offers a thorough, side-by-side comparison of ShoreTel and Avaya offerings to help you make informed decisions.
Compared with Cisco products, ShoreTel UC can offer numerous advantages, including streamlined deployment and management, easier scalability, and a significantly lower total cost of ownership (TCO).
This must-read publication features independent research from Gartner, providing a wealth of information around best in breed Unified Communication systems. 12 Unified Communications vendor ratings, along with their strengths and cautions, are provided.
Join us for this live web event where featured Forrester Research principal analyst, Art Schoeller and Interactive Intelligence senior vice president, Joe Staples will discuss these topics and help you be ready to take the best advantage of the upcoming year and the contribution your contact center can make to the success of your business.
Tune into this insightful webinar to see Riverbed Technology product marketing manager Joe Ghory present the facts on how you can ensure consistent performance wherever workers connect, get the most out of limited connectivity, and accomplish more by eliminating round trips and slow latency.
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
VMware recently announced VMware vFabric™ Data Director, a new database deployment and operations platform that enables enterprise IT organizations to offer database as a private cloud service. Built on top of VMware vSphere 5, vFabric Data Director enables IT organizations to ontrol database sprawl through automation and consistent policy enforcement and accelerate application development cycles with self-service database management. Attend this webcast to learn how vFabric Data Director can help you build database-as-a-service in your datacenter.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Sponsored Links
Resource Center