Feeds

BlackBerry squeezed by DoS security bugs

Three vulns but only one fixed

Choosing a cloud hosting partner with confidence

Research In Motion (RIM) has warned of a trio of vulnerabilities in its popular BlackBerry software that create a means for hackers to launch denial of service attacks. Patches are available to defend against only one of the vulnerabilities, but RIM has issued advice on how to guard against attack from the other two.

The most serious unfixed risk stems from a flaw in processing Server Routing Protocol (SRP) packets. This security bug creates a possible means to disrupt communication between BlackBerry Enterprise Server and BlackBerry Router, potentially disrupting service. A separate unpatched security bug in the handling of malformed Tiff image attachments creates a means for a remote hacker to launch denial of service attacks against the BlackBerry Attachment Service, providing an internal user is duped into viewing malicious files on a BlackBerry handheld.

The vulnerabilities have been reported in BlackBerry Enterprise Server 4.0 as well as later versions. Domino, Exchange and Novell GroupWise versions of the platform are all affected. Exploitation of the first vulnerability means a hacker needs to be able to connect to the BlackBerry Server or Router via port 3101/TCP. Shielding BlackBerry servers behind a firewall ought to thwart these attacks. Additionally, RIM advises users to exclude the processing of Tiff images as a workaround against the second threat, pending the availability of a more complete fix.

A third security bug - for which a fix has been made available - sees a BlackBerry handheld web browser vulnerable to a denial of service via a specially crafted Java Application Description (JAD) file. Users are advised to install BlackBerry device software version 4.0.2 or later to guard against attack.

Details of the vulnerabilities were outlined by FX of the Phenoelit group during a presentation at the 22nd Chaos Communication Congress in Berlin last week. US CERT has produced an overview of the vulnerabilities here.

In a statement, RIM said that it had "already developed software fixes for the issues identified by FX and, although there have been no customer reports of any actual problems, RIM has also provided temporary precautionary measures that can be taken in the meantime until customers are able to implement the software updates". ®

Internet Security Threat Report 2014

More from The Register

next story
Download alert: Nearly ALL top 100 Android, iOS paid apps hacked
Attack of the Clones? Yeah, but much, much scarier – report
Broadband sellers in the UK are UP TO no good, says Which?
Speedy network claims only apply to 10% of customers
Virgin Media struck dumb by NATIONWIDE packet loss balls-up
Turning it off and on again fixes glitch 12 HOURS LATER
Yahoo! blames! MONSTER! email! OUTAGE! on! CUT! CABLE! bungle!
Weekend woe for BT as telco struggles to restore service
Fujitsu CTO: We'll be 3D-printing tech execs in 15 years
Fleshy techie disses network neutrality, helmet-less motorcyclists
Facebook, working on Facebook at Work, works on Facebook. At Work
You don't want your cat or drunk pics at the office
Soz, web devs: Google snatches its Wallet off the table
Killing off web service in 3 months... but app-happy bonkers are fine
prev story

Whitepapers

Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
How to determine if cloud backup is right for your servers
Two key factors, technical feasibility and TCO economics, that backup and IT operations managers should consider when assessing cloud backup.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
The Heartbleed Bug: how to protect your business with Symantec
What happens when the next Heartbleed (or worse) comes along, and what can you do to weather another chapter in an all-too-familiar string of debilitating attacks?