[NEWS] RIM BlackBerry DoS (Meeting Location)

SecuriTeam <[email protected]>
Newsgroups gmane.comp.security.securiteam
Message-ID <[email protected]>
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html 

- - - - - - - - -



  RIM BlackBerry DoS (Meeting Location)
------------------------------------------------------------------------


SUMMARY

 <http://www.blackberry.com/> RIM BlackBerry is a Java-based wireless 
connectivity solution providing phone, e-mail, and other services on a 
variety of handheld devices. It is possible to reboot the Blackberry 
device by sending a specially crafted meeting request.

DETAILS

Vulnerable Systems:
 * RIM Blackberry 7230 with RIM BlackBerry Operating System software 
version 3.7.1.41. The Blackberry was synchronized with Microsoft Exchange 
server using Blackberry Enterprise Server for Microsoft Exchange.

Immune Systems:
 * The issue has been corrected in BlackBerry handheld software version 
3.8 and above.

Insufficient data validation for incoming calendar data makes possible to 
cause buffer overflow condition leading to stack corruption. As a result, 
it is possible to reboot the device (all stored messages will be lost 
since RAM storage will be reinitialized).

Example:
The issue can easily be reproduced by sending a standard Microsoft Outlook 
meeting request message with very long string (over 128K) in the Location: 
field.
To force immediate user notification, set meeting date/time to the past. 
The Blackberry reboots when it tries to notify the user. No user action is 
required. It is possible to render Blackberry device completely useless by 
queuing a number of such messages into user's mailbox.

Vendor Status:
The vendor has issued an official advisory which can be found at:  
<http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/7925/8142/Support_-_RIM_analysis_of_HexView_advisory_titled_BlackBerry_buffer_overflow,_DoS,_and_data_loss.html?nodeid=737173&vernum=11> Support - RIM analysis of HexView advisory titled BlackBerry buffer overflow, DoS, and data loss


ADDITIONAL INFORMATION

The information has been provided by  <mailto:[email protected]> hexview.
The original article can be found at:  
<http://www.hexview.com/docs/20041012-1.txt> 
http://www.hexview.com/docs/20041012-1.txt and:  
<http://www.hexview.com/docs/20041014-1.txt> 
http://www.hexview.com/docs/20041014-1.txt



======================================== 


This bulletin is sent to members of the SecuriTeam mailing list. 
To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] 
In order to subscribe to the mailing list, simply forward this email to: [email protected] 


==================== 
==================== 

DISCLAIMER: 
The information in this bulletin is provided "AS IS" without warranty of any kind. 
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.