We Suggest reading:
- KB03422 - HexView advisory on BlackBerry device buffer overflow and data loss.
- KB13142 - TeamOn Import Object ActiveX control vulnerability.
- KB16248 - Vulnerability exists in BlackBerry Application Web Loader ActiveX control.
- KB04791 - Corrupt Word file may cause buffer overflow in the BlackBerry Attachment Service.
- KB19701 - Vulnerability in the BlackBerry Desktop Manager allows remote code execution.
- KB00031 - Handheld not responding.
- KB00125 - BlackBerry Desktop Manager cannot detect the BlackBerry smartphone.
- KB00589 - BlackBerry Enterprise Solution security over the wireless network.
- KB03284 - Errors using the Nokia 6810, Nokia 6820, or Nokia 6822.
- KB03329 - Install BlackBerry Configuration.
HexView advisory on BlackBerry device buffer overflow and data lossContents [show] Products
Environment
Advisory posted: 29 October 2004 OverviewA HexView advisory (ID number HEXVIEW*2004*10*12*1) published on 12 October 2004 identified an issue in BlackBerry Device Software 3.7 Service Pack 1 that is known to Research In Motion (RIM) and has been corrected in BlackBerry Device Software 3.8 and later. The HexView advisory correctly identifies a scenario that can be manufactured to cause a BlackBerry device to reset, but RIM believes that the advisory contains several incorrect conclusions. While exploiting the software issue may cause a BlackBerry device to reset, it does not constitute a buffer overflow or data loss vulnerability. To date, RIM has not received any customer reports of this issue being exploited in practice. ImpactA BlackBerry device reset may occur. ProblemHexView published a brief advisory on 12 October 2004. HexView′s policy at that time was not to contact vendors in advance unless a vendor had a prior agreement with HexView. RIM was not notified in advance and was not able to provide any feedback to HexView prior to the publication of the advisory. RIM has since contacted HexView and HexView was helpful in assisting RIM with this issue. The advisory states the issue can be created by sending a Microsoft Outlook® meeting request with a large string (over 128 KB) in the Location field. It is important to note that Microsoft Outlook limits the size of the Location field to 255 characters, or bytes, so a large Location field cannot be normally or inadvertently created. Despite this restriction, RIM has replicated the issue defined by HexView on BlackBerry devices running BlackBerry Device Software 3.7 Service Pack 1 and confirmed that a BlackBerry device reset may occur. However, RIM believes the following conclusions in HexView′s advisory are incorrect:
Note: The Watchdog Timer also causes the BlackBerry device to reset. ResolutionInstall BlackBerry Device Software 3.8 or later. RIM has implemented further safeguards at the BlackBerry Enterprise Server level with the release of the following BlackBerry products:
These safety measures will prevent artificially large or problematic meeting requests from being delivered to the BlackBerry device. This eliminates the need for BlackBerry Device Software to be upgraded to version 3.8 or later. Additional InformationNote: HexView has posted an updated advisory (ID number HEXVIEW*2004*10*14*1). For more information on BlackBerry security, refer to the following documents:
Visit www.blackberry.com/security for more information on BlackBerry security. |