RETIRED: BlackBerry Enterprise Server Remote Code Execution Vulnerabilities
BID:49098
Info
RETIRED: BlackBerry Enterprise Server Remote Code Execution Vulnerabilities
| Bugtraq ID: | 49098 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2011 12:00AM |
| Updated: | Aug 10 2011 04:50PM |
| Credit: | The vendor reported these issues. |
| Vulnerable: |
Research In Motion Blackberry Enterprise Server for Novell Groupwise 5.0.1 MR3 Research In Motion Blackberry Enterprise Server for Novell Groupwise 5.0.1 Research In Motion Blackberry Enterprise Server for Novell Groupwise 4.1.7 Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 MR2 Research In Motion Blackberry Enterprise Server for Exchange 5.0.3 Research In Motion Blackberry Enterprise Server for Exchange 5.0.2 MR1 Research In Motion Blackberry Enterprise Server for Exchange 5.0.2 Research In Motion Blackberry Enterprise Server for Exchange 5.0.1 Research In Motion Blackberry Enterprise Server for Domino 5.0.3 Research In Motion Blackberry Enterprise Server for Domino 5.0.2 MR1 Research In Motion Blackberry Enterprise Server for Domino 5.0.2 Research In Motion Blackberry Enterprise Server for Domino 5.0.1 |
| Not Vulnerable: | |
Discussion
RETIRED: BlackBerry Enterprise Server Remote Code Execution Vulnerabilities
BlackBerry Enterprise Server is prone to multiple remote code-execution vulnerabilities.
Attackers can exploit these issues by enticing an unsuspecting user to open a specially crafted webpage.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the BlackBerry Enterprise Server login account.
This BID is being retired. The following individual records exist to better document the issues:
41174 libpng Memory Corruption and Memory Leak Vulnerabilities
43366 LibTIFF 'tiff' File Memory Corruption Vulnerability
41088 LibTIFF Multiple Remote Code Execution Vulnerabilities
46658 libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability
46951 libTIFF ThunderCode Decoder Heap Buffer Overflow Vulnerability
BlackBerry Enterprise Server is prone to multiple remote code-execution vulnerabilities.
Attackers can exploit these issues by enticing an unsuspecting user to open a specially crafted webpage.
Successful exploits can allow attackers to execute arbitrary code with the privileges of the BlackBerry Enterprise Server login account.
This BID is being retired. The following individual records exist to better document the issues:
41174 libpng Memory Corruption and Memory Leak Vulnerabilities
43366 LibTIFF 'tiff' File Memory Corruption Vulnerability
41088 LibTIFF Multiple Remote Code Execution Vulnerabilities
46658 libTIFF CCITT Group 4 Encoded TIFF Image Buffer Overflow Vulnerability
46951 libTIFF ThunderCode Decoder Heap Buffer Overflow Vulnerability
Exploit / POC
RETIRED: BlackBerry Enterprise Server Remote Code Execution Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
RETIRED: BlackBerry Enterprise Server Remote Code Execution Vulnerabilities
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
RETIRED: BlackBerry Enterprise Server Remote Code Execution Vulnerabilities
References:
References:
- Research In Motion Homepage (Research In Motion)
- Vulnerabilities in BlackBerry Enterprise Server components that process images c (Research In Motion)