We Suggest reading:
- KB04757 - Corrupt TIFF file may cause heap overflow resulting in Denial of Service in the BlackBerry Attachment Service.
- KB04756 - Corrupt PNG file may cause heap overflow in the BlackBerry Attachment Service.
- KB04791 - Corrupt Word file may cause buffer overflow in the BlackBerry Attachment Service.
- KB00115 - Forwarding attachments from the BlackBerry Wireless Handheld.
- KB01655 - Transaction error failure at service error appears when attempting to send an email from the BlackBerry smartphone.
- KB03265 - Supported attachment formats for the BlackBerry Internet Service.
- KB03662 - BlackBerry device users initializing after upgrade from BlackBerry Enterprise Server software version 2.2 to 4.0.
- KB04864 - Attachment Service.
- KB10172 - Unable to open attachments on the BlackBerry smartphone.
- KB10473 - Unable to open attachments on the BlackBerry smartphone.
Corrupt TIFF file may cause heap overflow resulting in Denial of Service in the BlackBerry Attachment ServiceContents [show] Products
Environment
Background
A presentation by FX of Phenoelit has identified an issue in the BlackBerry Enterprise Server that is known to Research In Motion® and has been corrected in current releases of the BlackBerry Enterprise Server. This article is in reference to US-Computer Emergency Readiness Team (US-CERT) Advisory VU#570768.
OverviewA corrupt Tagged Image File Format (TIFF) file sent to BlackBerry device users may prevent them from viewing attachments. ImpactProblemA corrupt TIFF file sent to a BlackBerry device user prevents the BlackBerry device user from viewing attachments.
The BlackBerry Attachment Service automatically restarts either immediately or within a specified time period (the default is 25 minutes). The administrator can manually restart the BlackBerry Attachment Service at any time. ResolutionTo resolve this problem, complete the steps below that correspond to your environment.
Microsoft Exchange
For BlackBerry Enterprise Server software version 4.0, install Service Pack 3, then install software version 4.0 Service Pack 3 Hotfix 3.
IBM Lotus Domino
For BlackBerry Enterprise Server software version 4.0, install Service Pack 3, then install software version 4.0 Service Pack 3 Hotfix 4.
Novell GroupWise
Install BlackBerry Enterprise Server software version 4.0 Service Pack 3, then install software version 4.0 Service Pack 3 Hotfix 1.
Note: To obtain the BlackBerry Enterprise Server software, go to the BlackBerry Software Download Information web site. WorkaroundAn administrator can exclude TIFF images from being processed by the BlackBerry Attachment Service in the BlackBerry Enterprise Server, or disable the Attachment Service completely.
To exclude TIFF images from being processed by the BlackBerry Attachment Service, complete the following steps:
For Microsoft Exchange and Novell GroupWise, follow these additional steps:
For IBM Lotus Domino, follow these additional steps:
Even though the .tiff and .tif extensions have been removed from the list of supported file types, the BlackBerry Attachment Service may automatically detect a TIFF file with a renamed extension and attempt to process the file. Administrators may need to disable the image attachment distiller.
To disable the image attachment distiller, complete the following steps:
For Microsoft Exchange and Novell GroupWise, follow these additional steps:
For IBM Lotus Domino, follow these additional steps:
Additional InformationVisit www.blackberry.com/security for more information on BlackBerry security. |