Blackberry Enterprise Server Attachment Service PNG Attachment Denial Of Service Vulnerability
BID:16204
Info
Blackberry Enterprise Server Attachment Service PNG Attachment Denial Of Service Vulnerability
| Bugtraq ID: | 16204 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-2344 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 10 2006 12:00AM |
| Updated: | Jan 10 2006 12:00AM |
| Credit: | Discovery is credited to FX of Phenoelit. |
| Vulnerable: |
Symantec Clientless VPN Gateway 4400 Series 4.0 SP2 Symantec Clientless VPN Gateway 4400 Series 4.0 SP1 Rim Blackberry Enterprise Server for Exchange 4.0 SP1 Rim Blackberry Enterprise Server for Domino 4.0 Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 SP2 Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 SP1 Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 HP OpenCall MultiService Controller 4.0 SP2 HP OpenCall MultiService Controller 4.0 |
| Not Vulnerable: |
Symantec Clientless VPN Gateway 4400 Series 4.0 SP3 Nortel Networks Contivity 4600 Secure IP Services Gateway 4.0 SP3 HP OpenCall MultiService Controller 4.0 SP3 |
Discussion
Blackberry Enterprise Server Attachment Service PNG Attachment Denial Of Service Vulnerability
Research In Motion Blackberry Enterprise Server is prone to denial of service attacks. This issue affects the Attachment Service and may be triggered by a malformed PNG attachment.
The issue is caused by a heap-based buffer overflow. This issue allows remote attackers to execute arbitrary machine code in the context of the affected Attachment Service. Failed exploitation attempts will likely cause a denial of service in the affected application.
Research In Motion Blackberry Enterprise Server is prone to denial of service attacks. This issue affects the Attachment Service and may be triggered by a malformed PNG attachment.
The issue is caused by a heap-based buffer overflow. This issue allows remote attackers to execute arbitrary machine code in the context of the affected Attachment Service. Failed exploitation attempts will likely cause a denial of service in the affected application.
Exploit / POC
Blackberry Enterprise Server Attachment Service PNG Attachment Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Blackberry Enterprise Server Attachment Service PNG Attachment Denial Of Service Vulnerability
Solution:
The vendor has released an advisory, along with fixes to address this issue. Please see the referenced advisory for information on obtaining fixes.
Solution:
The vendor has released an advisory, along with fixes to address this issue. Please see the referenced advisory for information on obtaining fixes.
References
Blackberry Enterprise Server Attachment Service PNG Attachment Denial Of Service Vulnerability
References:
References: