Home > Security News > Security Bytes: Flaws found in BlackBerry Server
Security News:
EMAIL THIS

Security Bytes: Flaws found in BlackBerry Server

By SearchSecurity.com Staff
04 Jan 2006 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Flaws found in BlackBerry server
Waterloo, Ontario-based Research In Motion Ltd. (RIM) has acknowledged that attackers could exploit flaws in its BlackBerry Enterprise Server to cause a denial-of-service. But the vendor has developed a workaround. Danish vulnerability clearinghouse Secunia issued its own advisory describing two problems:

  • An error in how malformed TIFF image attachments are handled can be exploited to prevent a BlackBerry user from viewing attachments.
  • An error in how Server Routing Protocol (SRP) packets are handled can be exploited to disrupt the communication between the BlackBerry Enterprise Server and BlackBerry Router service, potentially causing a denial of service.

Secunia noted that successful exploitation requires that the attacker is able to connect to the BlackBerry Server/Router via TCP port 3101.

As a workaround, RIM recommends ensuring TIFF images aren't processed by the attachment service and/or disabling the image attachment distiller. The vendor added that the BlackBerry Enterprise Server and the BlackBerry Router should be placed behind the firewall in a trusted network segment.

SS numbers of H&R Block customers reportedly exposed
H&R Block Inc. has sent a letter to customers warning that those who received free copies of its TaxCut software may have had their Social Security numbers exposed. H&R Block learned of the slip-up in late December, after a customer informed the company that a unique ID that appeared on the package, above the mailing label, contained his or her Social Security number, according to a report from eWeek. The Social Security number was used as part of a unique, 47-digit tracking number. Denise Sposato, a spokesperson for H&R Block, told eWeek that the number would be impossible to spot and that no customer data has been lost or stolen as a result of the mistake. The Kansas City, Mo.-based company believes that less than 3% of those who were mailed a copy of TaxCut had their Social Security numbers used.

Multiple flaws found in Linux kernel
Attackers could exploit multiple security holes in the Linux kernel to cause a denial of service or gain elevated user privileges. The French Security Incident Response Team (FrSIRT) outlined four problems in an advisory:

  • Local attackers could exploit an error in how policy system calls are handled to cause a denial of service.
  • A one-byte buffer overrun error in "kernel/sysctl.c" that appears when overly long user-supplied strings are processed could be exploited by local attackers to execute arbitrary commands.
  • An error in "net/ipv4/fib_frontend.c" that appears when malformed "fib_lookup" netlink messages are processed could cause illegal memory references.
  • A buffer overflow error in the CA-driver for TwinHan DST Frontend/Card [drivers/media/dvb/bt8xx/dst_ca.c] could be exploited by malicious users to cause a denial of service or potentially execute arbitrary commands.

Linux Kernel version 2.6.x, first released last year, is affected. FrSIRT recommends users upgrade to Linux Kernel 2.6.15.

Tags: Information Security Laws, Investigations and EthicsApplication Attacks (Buffer Overflows, Cross-Site Scripting)IM Security Issues, Risks and ToolsWireless Network Protocols and StandardsHandheld and Mobile Device Security Best PracticesInformation Security Incident ResponseEmail Security Guidelines, Encryption and AppliancesAlternative OS security: Mac, Linux, Unix, etc.Smartphone and PDA Viruses and ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Information Security Laws, Investigations and Ethics
Cybersecurity czar candidate questions clout of new position
DHS fills National Cybersecurity Center post
FTC shutters rogue ISP for hosting malicious content, botnets
Experts optimistic of Obama cybersecurity plan
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Cybersecurity Act of 2009: Power grab, or necessary step?
Face-off: Who should be in charge of cybersecurity?
Feds should get private sector advice on cybersecurity
Federal efforts to secure cyberinfrastrucure

Application Attacks (Buffer Overflows, Cross-Site Scripting)
Adobe ColdFusion websites being compromised
PCI management: The case for Web application firewalls
Month of Twitter Bugs project to document Twitter flaws
Adobe issues first quarterly patch release fixing 13 flaws
Balancing security and performance: Protecting layer 7 on the network
Adobe issues Reader update fixing zero-day flaw
The Pipe Dream of No More Free Bugs
Security Squad: Federal cybersecurity defenses
Oracle issues 43 updates, fixes serious database flaws
Attackers target new Microsoft PowerPoint zero-day flaw
Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

IM Security Issues, Risks and Tools
What are effective ways to stop instant messaging (IM) spam?
Secure messaging complications result in limited protection
Is it possible to ban chat programs on an enterprise LAN?
How to lock down instant messaging in the enterprise
AOL closes AIM attack vector, but risks remain
Researcher says AIM still vulnerable, AOL insists it's fixed
Serious security flaw in AOL Instant Messenger
Security flaws found in AOL, Yahoo IM programs
Flaw found in MSN Messenger
AOL, Yahoo, Trillian IM applications under threat

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CALEA  (SearchSecurity.com)
cyberstalking  (SearchSecurity.com)
cypherpunk  (SearchSecurity.com)
HSPD-7  (SearchSecurity.com)
I-SPY Act  (SearchSecurity.com)
Information Awareness Office  (SearchSecurity.com)
intelligence community  (SearchSecurity.com)
lawful interception  (SearchSecurity.com)
lifestyle polygraph  (SearchSecurity.com)
vulnerability disclosure  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts