 |
|
|
Family: Gain root remotely --> Category: infos
BlackBerry Enterprise Server Attachment Buffer Overflow Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary Checks version number of BlackBerry Enterprise Server
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote Windows application is affected by multiple buffer overflow
vulnerabilities.
Description :
The version of BlackBerry Enterprise Server on the remote host
reportedly contains flaws in its handling of Word and TIFF document
attachments that may result in buffer overflows when a user opens a
malformed file on a BlackBerry device. A remote attacker may be able
to exploit this issue to execute code on the affected host subject to
the rights under which the application runs, generally
'Administrator'.
See also :
http://blogs.washingtonpost.com/securityfix/2006/01/security_hole_e.html
http://www.nessus.org/u?c224cef8
http://www.nessus.org/u?f9d6cf39
Solution :
Install the appropriate service pack / hotfix as described in the
vendor advisory referenced above.
Threat Level:
High / CVSS Base Score : 7.0
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|
|
|
|
|