[NEWS] RIM BlackBerry DoS (Meeting Location)
SecuriTeam <[email protected]>
| Newsgroups | gmane.comp.security.securiteam |
|---|---|
| Message-ID | <[email protected]> |
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com - - promotion The SecuriTeam alerts list - Free, Accurate, Independent. Get your security news from a reliable source. http://www.securiteam.com/mailinglist.html - - - - - - - - - RIM BlackBerry DoS (Meeting Location) ------------------------------------------------------------------------ SUMMARY <http://www.blackberry.com/> RIM BlackBerry is a Java-based wireless connectivity solution providing phone, e-mail, and other services on a variety of handheld devices. It is possible to reboot the Blackberry device by sending a specially crafted meeting request. DETAILS Vulnerable Systems: * RIM Blackberry 7230 with RIM BlackBerry Operating System software version 3.7.1.41. The Blackberry was synchronized with Microsoft Exchange server using Blackberry Enterprise Server for Microsoft Exchange. Immune Systems: * The issue has been corrected in BlackBerry handheld software version 3.8 and above. Insufficient data validation for incoming calendar data makes possible to cause buffer overflow condition leading to stack corruption. As a result, it is possible to reboot the device (all stored messages will be lost since RAM storage will be reinitialized). Example: The issue can easily be reproduced by sending a standard Microsoft Outlook meeting request message with very long string (over 128K) in the Location: field. To force immediate user notification, set meeting date/time to the past. The Blackberry reboots when it tries to notify the user. No user action is required. It is possible to render Blackberry device completely useless by queuing a number of such messages into user's mailbox. Vendor Status: The vendor has issued an official advisory which can be found at: <http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/7925/8142/Support_-_RIM_analysis_of_HexView_advisory_titled_BlackBerry_buffer_overflow,_DoS,_and_data_loss.html?nodeid=737173&vernum=11> Support - RIM analysis of HexView advisory titled BlackBerry buffer overflow, DoS, and data loss ADDITIONAL INFORMATION The information has been provided by <mailto:[email protected]> hexview. The original article can be found at: <http://www.hexview.com/docs/20041012-1.txt> http://www.hexview.com/docs/20041012-1.txt and: <http://www.hexview.com/docs/20041014-1.txt> http://www.hexview.com/docs/20041014-1.txt ======================================== This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] In order to subscribe to the mailing list, simply forward this email to: [email protected] ==================== ==================== DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.