Blackberry Handheld JAD File Browser Denial Of Service Vulnerability
BID:16099
Info
Blackberry Handheld JAD File Browser Denial Of Service Vulnerability
| Bugtraq ID: | 16099 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2005-2343 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 30 2005 12:00AM |
| Updated: | Dec 30 2005 12:00AM |
| Credit: | Discovery is credited to FX of Phenoelit. |
| Vulnerable: |
Rim Blackberry Device Software 4.0 Rim Blackberry Desktop Manager Rim Blackberry 8700r Rim Blackberry 8700f Rim Blackberry 8700c Rim Blackberry 7780 Rim Blackberry 7750 Rim Blackberry 7730 Rim Blackberry 7520 Rim Blackberry 7290 Rim Blackberry 7280 Rim Blackberry 7250 Rim Blackberry 7230 4.0 Rim Blackberry 7230 3.8 Rim Blackberry 7230 3.7.1 .41 Rim Blackberry 7130e Rim Blackberry 7105t Rim Blackberry 7100x Rim Blackberry 7100v Rim Blackberry 7100t Rim Blackberry 7100r Rim Blackberry 7100i Rim Blackberry 7100g |
| Not Vulnerable: |
Rim Blackberry Device Software 4.0.2 |
Discussion
Blackberry Handheld JAD File Browser Denial Of Service Vulnerability
Blackberry Handheld devices are prone to a denial of service attack. The embedded Web browser will stop responding due to a dialog box that has not been properly dismissed when handling a malformed JAD (Java Application Description) file.
Blackberry Handheld devices are prone to a denial of service attack. The embedded Web browser will stop responding due to a dialog box that has not been properly dismissed when handling a malformed JAD (Java Application Description) file.
Exploit / POC
Blackberry Handheld JAD File Browser Denial Of Service Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
Blackberry Handheld JAD File Browser Denial Of Service Vulnerability
Solution:
The vendor has addressed this issue in version 4.0.2 of the Blackberry Device Software. Affected users are encouraged to contact their service providers to obtain updated software.
Solution:
The vendor has addressed this issue in version 4.0.2 of the Blackberry Device Software. Affected users are encouraged to contact their service providers to obtain updated software.
References
Blackberry Handheld JAD File Browser Denial Of Service Vulnerability
References:
References:
- Support - Browser dialogue box not properly dismissed after downloading a corrup (Research In Motion)