Blackberry Browser Multiple Unspecified Information Disclosure and Integer Overflow Vulnerabilities

BID:46833

Info

Blackberry Browser Multiple Unspecified Information Disclosure and Integer Overflow Vulnerabilities

Bugtraq ID: 46833
Class: Unknown
CVE:
Remote: Yes
Local: No
Published: Mar 10 2011 12:00AM
Updated: Mar 14 2011 02:47PM
Credit: Willem Pinckaers, Vincenzo Iozzo and Ralf-Philipp Weinmann
Vulnerable: Research In Motion Blackberry Torch 9800 0
Research In Motion Blackberry Pearl 8100 0
Research In Motion Blackberry Curve 8300 0
Research In Motion Blackberry Browser 0
Research In Motion Blackberry 9700 5.0.0.593
Research In Motion Blackberry 8800 4.2
Research In Motion Blackberry 8800 4.1
Research In Motion Blackberry 8800 0
Research In Motion Blackberry 8720 4.2
Research In Motion Blackberry 8720 4.1
Research In Motion Blackberry 8700r
Research In Motion Blackberry 8700f
Research In Motion Blackberry 8700c
Research In Motion Blackberry 8320 4.2
Research In Motion Blackberry 8320 4.1
Research In Motion Blackberry 7780
Research In Motion Blackberry 7750
Research In Motion Blackberry 7730
Research In Motion Blackberry 7520
Research In Motion Blackberry 7290
Research In Motion Blackberry 7280
Research In Motion BlackBerry 7270 0
Research In Motion Blackberry 7250
Research In Motion Blackberry 7230 4.0
Research In Motion Blackberry 7230 3.8
Research In Motion Blackberry 7230 3.7.1 .41
Research In Motion Blackberry 7130e
Research In Motion Blackberry 7105t
Research In Motion Blackberry 7100x
Research In Motion Blackberry 7100v
Research In Motion Blackberry 7100t
Research In Motion Blackberry 7100r
Research In Motion Blackberry 7100i
Research In Motion Blackberry 7100g
Research In Motion BlackBerry 9700
Research In Motion BlackBerry 9650
Research In Motion BlackBerry 8530
Research In Motion BlackBerry 8520
Research In Motion BlackBerry 8330
Not Vulnerable:

Discussion

Blackberry Browser Multiple Unspecified Information Disclosure and Integer Overflow Vulnerabilities

Blackberry's web browser is affected by multiple information disclosure vulnerabilities.

An attacker can exploit these issues by enticing an unsuspecting user into viewing a specially crafted website. A successful exploit will result in the disclosure of potentially sensitive information.

Specific affected devices are not currently known. This BID will be updated as more information emerges.

NOTE: This document previously also covered an integer-overflow vulnerability. That issue is now covered in BID 46849 (WebKit Style Handling Memory Corruption Vulnerability) to better document it.

Exploit / POC

Blackberry Browser Multiple Unspecified Information Disclosure and Integer Overflow Vulnerabilities

These issues were successfully exploited at CanSecWest's 2011 Pwn2Own contest. The exploit is not known to be public or in the wild.

Solution / Fix

Blackberry Browser Multiple Unspecified Information Disclosure and Integer Overflow Vulnerabilities

Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

References

Blackberry Browser Multiple Unspecified Information Disclosure and Integer Overflow Vulnerabilities

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report