Home > Security News > RIM updates BlackBerry Desktop Software to fix ActiveX flaw
Security News:
EMAIL THIS

RIM updates BlackBerry Desktop Software to fix ActiveX flaw

By SearchSecurity.com Staff
08 Dec 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Research In Motion has quietly released an update to its BlackBerry Desktop Manager, fixing an ActiveX vulnerability in the Roxio Media Manager that could be exploited by an attacker to cause a buffer overflow.

RIM uses the media manager to synchronize BlackBerrys and PCs running Microsoft Windows. In its advisory to customers issued Nov. 27, RIM said the flaw could be exploited if a user visits a malicious website that invokes the control. The company urged its customers to upgrade to the latest patch for the BlackBerry Desktop Software version 4.5, 4.6 or 4.7.

The problem is in FLEXnet Connect (acquired by Accresso Software from Macrovision), a software package that allows vendors to provide updates to applications, according to a vulnerability note issued by the United States Computer Emergency Readiness Team (US-CERT). As a workaround, US-CERT said companies could disable ActiveX controls in the Internet Zone.

RIM also issued recommendations on setting administrative roles in the BlackBerry Enterprise Server. The server's management console allows an administrator to set roles based on a person's job responsibilities.

"Research In Motion (RIM) recommends that the administrative roles in the BlackBerry Manager be used only to group trusted administrators according to the scope of their administrative responsibility, not for an explicit security purpose, such as limiting access to sensitive data," RIM said in a document issued to customers.



Tags: Handheld and Mobile Device Security Best PracticesSmartphone and PDA Viruses and ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Handheld and Mobile Device Security Best Practices
Unified communications: Securing a converged infrastructure
RIM patches serious BlackBerry Attachment Service flaws
How secure are iPhone App Store mobile applications?
Is there a spy on my mobile device?
Mobile phones win during Pwn2Own contest
Latest Apple iPhone features prompt security concerns
Apple iPhone app could boost two-factor
What Obama's Blackberry means for mobile device security
SMS mobile worm attacks Symbian smartphones
Smartphone security lacking at many businesses
Handheld and Mobile Device Security Best Practices Research

Smartphone and PDA Viruses and Threats
Unified communications: Securing a converged infrastructure
RIM patches serious BlackBerry Attachment Service flaws
Latest Apple iPhone features prompt security concerns
SMS mobile worm attacks Symbian smartphones
Smartphone security lacking at many businesses
RIM warns of serious vulnerability in BlackBerry Web loader
RIM fixes serious BlackBerry PDF handling flaws
How easily can spyware be placed on a mobile phone?
Should enterprises ban USBs because the DoD banned them?
Do mobile devices put sensitive data at risk when used overseas?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts