Go Back   BlackBerry Forums > BlackBerry General Forums > BlackBerry Announcements

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 15-07-2007, 05:41 PM
BESadmin's Avatar
Administrator
 
Join Date: Aug 2006
Posts: 1,774
HexView advisory on BlackBerry device buffer overflow and data loss

HexView advisory on BlackBerry device buffer overflow and data loss

Doc ID : KB03422
Last Modified : 2007-07-06
Document Type : Security Advisory

Environment

Advisory Posted: 29 October 2004
  • BlackBerry® device
  • BlackBerry® Device Software 3.7 Service Pack 1
  • BlackBerry® Enterprise Server
  • IBM® Lotus® Domino®
  • Microsoft® Exchange
Overview

A HexView advisory (ID number HEXVIEW*2004*10*12*1) published on 12 October 2004 identified an issue in BlackBerry Device Software 3.7 Service Pack 1 that is known to Research In Motion (RIM) and has been corrected in BlackBerry Device Software 3.8 and later.

The HexView advisory correctly identifies a scenario that can be manufactured to cause a BlackBerry device to reset, but RIM believes that the advisory contains several incorrect conclusions. While exploiting the software issue may cause a BlackBerry device to reset, it does not constitute a buffer overflow or data loss vulnerability. To date, RIM has not received any customer reports of this issue being exploited in practice.

Impact

A BlackBerry device reset may occur.

Problem

HexView published a brief advisory on 12 October 2004. HexView's policy at that time was not to contact vendors in advance unless a vendor had a prior agreement with HexView. RIM was not notified in advance and was not able to provide any feedback to HexView prior to the publication of the advisory. RIM has since contacted HexView and HexView was helpful in assisting RIM with this issue.

The advisory states the issue can be created by sending a Microsoft Outlook® meeting request with a large string (over 128 KB) in the Location field. It is important to note that Microsoft Outlook limits the size of the Location field to 255 characters, or bytes, so a large Location field cannot be normally or inadvertently created. Despite this restriction, RIM has replicated the issue defined by HexView on BlackBerry devices running BlackBerry Device Software 3.7 Service Pack 1 and confirmed that a BlackBerry device reset may occur. However, RIM believes the following conclusions in HexView's advisory are incorrect:
  • A buffer overflow and stack corruption occur.
  • Stored messages and BlackBerry device user data are lost. (These are stored in non-volatile Flash memory, not in RAM.)
  • Malicious code can be embedded and executed on the BlackBerry device.
Note: The Watchdog Timer also causes the BlackBerry device to reset.

Resolution

Install BlackBerry Device Software 3.8 or later.
RIM has implemented further safeguards at the BlackBerry Enterprise Server level with the release of the following BlackBerry products:
  • BlackBerry Enterprise Server software version 4.0
  • BlackBerry Enterprise Server software version 3.6 Service Pack 4 Hot Fix 1 for Microsoft Exchange
  • BlackBerry Enterprise Server software version 2.2 Service Pack 4 Hot Fix 1 for IBM Lotus Domino
These safety measures will prevent artificially large or problematic meeting requests from being delivered to the BlackBerry device. This eliminates the need for BlackBerry Device Software to be upgraded to version 3.8 or later.

Additional Information

Note: HexView has posted an updated advisory (ID number HEXVIEW*2004*10*14*1).
For more information on BlackBerry security, refer to the following documents:
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT +11. The time now is 01:05 PM.

Copyright ©2006 - 2008 BLACKBERRYFORUMS - RIM and Blackberry are Registered Trademarks of Research In Motion


Search Engine Friendly URLs by vBSEO 3.2.0