Overview
A buffer overflow vulnerability in BlackBerry Enterprise Server may allow a remote attacker to execute arbitrary code.
Description
A buffer overflow vulnerability exists in the BlackBerry Attachment Service component of BlackBerry Enterprise Server. This vulnerability may allow a remote attacker to execute arbitrary code when the service fails to handle a malformed Microsoft Word (.doc) document. BlackBerry states that the following systems are vulnerable:
|
Impact
A remote attacker who can successfully convince a user to open a malicious Microsoft Word attachment on a BlackBerry Handheld device may be able to execute arbitrary code and compromise a vulnerable server. |
Solution
BlackBerry provides the following solutions:
IBM Lotus Domino
Novell GroupWise
|
Workarounds
Even though the .doc extension has been removed from the list of supported file types, the Attachment Service may automatically detect a .doc file with a renamed extension and attempt to process the file. Administrators may need to disable the Attachment Service. To disable the Attachment Service
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported by BlackBerry.
This document was written by Katie Washok.
Other Information
CVE IDs: | CVE-2006-0761 |
Severity Metric: | 0.59 |
Date Public: | 2006-02-09 |
Date First Published: | 2006-08-21 |
Date Last Updated: | 2006-08-21 17:46 UTC |
Document Revision: | 14 |