|
|
|
![]() |
Vulnerability Note VU#829400Research in Motion (RIM) BlackBerry Handheld web browser does not properly handle Java Application Description (JAD) filesOverviewThe Research in Motion (RIM) BlackBerry Handheld web browser is vulnerable to a denial of service via a specially crafted Java Application Description (JAD) file.I. DescriptionThe BlackBerry Handheld web browser does not properly handle malformed JAD files. JAD files in J2ME are used to describe Java applications (icons, size, description, vendor, platform requirements, etc) to the BlackBerry Handheld. From RIM Technical Knowledge Center article KB-04755:If the JAD file is formatted to contain a long application name and vendor string (i.e., 256 or more characters) to your BlackBerry device, the browser appears to stop responding. II. ImpactBy convincing a user to access a specially crafted JAD file, an unauthenticated, remote attacker could cause the browser to hang.III. SolutionUpgradeAccording to RIM Technical Knowledge Center article KB-04755: "Install BlackBerry Device Software 4.0.2 or later. To obtain the most recent version of the device software, contact your service provider."
References
This vulnerability was reported by FX of Phenoelit. Thanks to RIM for information used in this document. This document was written by Art Manion.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||