Vulnerability Note VU#829400

Research in Motion (RIM) BlackBerry Handheld web browser does not properly handle Java Application Description (JAD) files

Original Release date: 31 Dec 2005 | Last revised: 31 Dec 2005

Overview

The Research in Motion (RIM) BlackBerry Handheld web browser is vulnerable to a denial of service via a specially crafted Java Application Description (JAD) file.

Description

The BlackBerry Handheld web browser does not properly handle malformed JAD files. JAD files in J2ME are used to describe Java applications (icons, size, description, vendor, platform requirements, etc) to the BlackBerry Handheld. From RIM Technical Knowledge Center article KB-04755:

    If the JAD file is formatted to contain a long application name and vendor string (i.e., 256 or more characters) to your BlackBerry device, the browser appears to stop responding.
    ...
    A browser dialog is not properly dismissed. The browser displays the application name or vendor string on the download screen (this appears as several lines). The long application name indicates that there may be problems with the JAD file and caution should be exercised when downloading the application.

Impact

By convincing a user to access a specially crafted JAD file, an unauthenticated, remote attacker could cause the browser to hang.

Solution

Upgrade
According to RIM Technical Knowledge Center article KB-04755: "Install BlackBerry Device Software 4.0.2 or later. To obtain the most recent version of the device software, contact your service provider."


Bypass browser dialog

To bypass the browser dialog, start a new browser application, or click on a URL from an email message.

Reset BlackBerry Handheld device

If necessary, reset the BlackBerry Handheld by removing and re-inserting the battery.

Systems Affected (Learn More)

VendorStatusDate NotifiedDate Updated
Research in Motion (RIM)Affected-31 Dec 2005
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A N/A

References

Credit

This vulnerability was reported by FX of Phenoelit. Thanks to RIM for information used in this document.

This document was written by Art Manion.

Other Information

  • CVE IDs: CAN-2005-2343
  • Date Public: 27 Dec 2005
  • Date First Published: 31 Dec 2005
  • Date Last Updated: 31 Dec 2005
  • Severity Metric: 2.46
  • Document Revision: 8

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.