Mon, Feb 13 2006 5:58 Don

BlackBerry Enterprise Server Word Document Buffer Overflow Vulnerability

Technical Description

A vulnerability has been identified in BlackBerry Enterprise Server, which may be exploited by remote attackers to execute arbitrary code. This flaw is due to a buffer overflow error in the BlackBerry Attachment Service component that does not properly handle malformed Word (.doc) documents, which could be exploited by an unauthenticated remote attacker to compromise a vulnerable server by convincing a user to open a malicious attachment on a BlackBerry Handheld.

Affected Products

BlackBerry Enterprise Server version 2.2 and later for Lotus Domino
BlackBerry Enterprise Server version 3.6 and later for MS Exchange
BlackBerry Enterprise Server version 4.0 and later for Novell GroupWise

Solution

Apply security updates :
http://www.blackberry.com/support/downloads/index.shtml

References

http://www.frsirt.com/english/advisories/2006/0530
http://www.frsirt.com/english/reference/5737


FrSIRT/ADV-2006-0530
Filed under: