Blackberry Enterprise Server Attachment Service TIFF Attachment Denial Of Service Vulnerability
BID:16098
Info
Blackberry Enterprise Server Attachment Service TIFF Attachment Denial Of Service Vulnerability
| Bugtraq ID: | 16098 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-2341 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 30 2005 12:00AM |
| Updated: | Dec 30 2005 12:00AM |
| Credit: | Discovery is credited to FX of Phenoelit. |
| Vulnerable: |
Rim Blackberry Enterprise Server for Exchange 4.0 SP1 Rim Blackberry Enterprise Server for Domino 4.0 |
| Not Vulnerable: | |
Discussion
Blackberry Enterprise Server Attachment Service TIFF Attachment Denial Of Service Vulnerability
Research In Motion Blackberry Enterprise Server is prone to denial of service attacks. This issue affects the Attachment Service and may be triggered by a malformed TIFF attachment.
The issue is reportedly caused by a heap-based buffer overflow. The vendor has stated that this issue will result in a denial of service, and it is therefore not believed that the issue is exploitable beyond a denial of service. However, other sources indicate that this issue may allow arbitrary code execution to occur upon successful exploitation. Specific details regarding code execution are not currently available and have not been confirmed. This record will be updated when more information is available.
Research In Motion Blackberry Enterprise Server is prone to denial of service attacks. This issue affects the Attachment Service and may be triggered by a malformed TIFF attachment.
The issue is reportedly caused by a heap-based buffer overflow. The vendor has stated that this issue will result in a denial of service, and it is therefore not believed that the issue is exploitable beyond a denial of service. However, other sources indicate that this issue may allow arbitrary code execution to occur upon successful exploitation. Specific details regarding code execution are not currently available and have not been confirmed. This record will be updated when more information is available.
Exploit / POC
Blackberry Enterprise Server Attachment Service TIFF Attachment Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Blackberry Enterprise Server Attachment Service TIFF Attachment Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Blackberry Enterprise Server Attachment Service TIFF Attachment Denial Of Service Vulnerability
References:
References:
- Known Issues - Corrupt TIFF file may cause heap overflow resulting in denial of (Research In Motion)
- Security Hole Claimed for BlackBerrys (Security Fix)