Blackberry Handheld JAD File Browser Denial Of Service Vulnerability

BID:16099

Info

Blackberry Handheld JAD File Browser Denial Of Service Vulnerability

Bugtraq ID: 16099
Class: Failure to Handle Exceptional Conditions
CVE: CVE-2005-2343
Remote: Yes
Local: No
Published: Dec 30 2005 12:00AM
Updated: Dec 30 2005 12:00AM
Credit: Discovery is credited to FX of Phenoelit.
Vulnerable: Rim Blackberry Device Software 4.0
Rim Blackberry Desktop Manager
Rim Blackberry 8700r
Rim Blackberry 8700f
Rim Blackberry 8700c
Rim Blackberry 7780
Rim Blackberry 7750
Rim Blackberry 7730
Rim Blackberry 7520
Rim Blackberry 7290
Rim Blackberry 7280
Rim Blackberry 7250
Rim Blackberry 7230 4.0
Rim Blackberry 7230 3.8
Rim Blackberry 7230 3.7.1 .41
Rim Blackberry 7130e
Rim Blackberry 7105t
Rim Blackberry 7100x
Rim Blackberry 7100v
Rim Blackberry 7100t
Rim Blackberry 7100r
Rim Blackberry 7100i
Rim Blackberry 7100g
Not Vulnerable: Rim Blackberry Device Software 4.0.2

Discussion

Blackberry Handheld JAD File Browser Denial Of Service Vulnerability

Blackberry Handheld devices are prone to a denial of service attack. The embedded Web browser will stop responding due to a dialog box that has not been properly dismissed when handling a malformed JAD (Java Application Description) file.

Exploit / POC

Blackberry Handheld JAD File Browser Denial Of Service Vulnerability

There is no exploit required.

Solution / Fix

Blackberry Handheld JAD File Browser Denial Of Service Vulnerability

Solution:
The vendor has addressed this issue in version 4.0.2 of the Blackberry Device Software. Affected users are encouraged to contact their service providers to obtain updated software.

References

Blackberry Handheld JAD File Browser Denial Of Service Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report