Home > Security News > RIM updates BlackBerry Desktop Software to fix ActiveX flaw
Security News:
EMAIL THIS

RIM updates BlackBerry Desktop Software to fix ActiveX flaw

By SearchSecurity.com Staff
08 Dec 2008 | SearchSecurity.com

Security Wire Daily News
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google

Research In Motion has quietly released an update to its BlackBerry Desktop Manager, fixing an ActiveX vulnerability in the Roxio Media Manager that could be exploited by an attacker to cause a buffer overflow.

RIM uses the media manager to synchronize BlackBerrys and PCs running Microsoft Windows. In its advisory to customers issued Nov. 27, RIM said the flaw could be exploited if a user visits a malicious website that invokes the control. The company urged its customers to upgrade to the latest patch for the BlackBerry Desktop Software version 4.5, 4.6 or 4.7.

The problem is in FLEXnet Connect (acquired by Accresso Software from Macrovision), a software package that allows vendors to provide updates to applications, according to a vulnerability note issued by the United States Computer Emergency Readiness Team (US-CERT). As a workaround, US-CERT said companies could disable ActiveX controls in the Internet Zone.

RIM also issued recommendations on setting administrative roles in the BlackBerry Enterprise Server. The server's management console allows an administrator to set roles based on a person's job responsibilities.

"Research In Motion (RIM) recommends that the administrative roles in the BlackBerry Manager be used only to group trusted administrators according to the scope of their administrative responsibility, not for an explicit security purpose, such as limiting access to sensitive data," RIM said in a document issued to customers.



Tags: Handheld and Mobile Device Security Best PracticesSmartphone and PDA Viruses and ThreatsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Handheld and Mobile Device Security Best Practices
Screencast: Find rogue wireless acess points with Vistumbler
Secure your remote users in 2010
Researchers find thousands of flawed embedded devices
Best Mobile Data Security Products
Should Windows Mobile updates come from Microsoft?
MMS messaging spoof hack could have global ramifications
How to prevent mobile phone spying
Unified communications: Securing a converged infrastructure
RIM patches serious BlackBerry Attachment Service flaws
How secure are iPhone App Store mobile applications?
Handheld and Mobile Device Security Best Practices Research

Smartphone and PDA Viruses and Threats
iPhone worm Rickrolls jailbroken phones
US-CERT warns of BlackBerry snooping software
Mini guide: How to remove and prevent Trojans, malware and spyware
SMS attacks against BlackBerry certificate flaw possible
MMS messaging spoof hack could have global ramifications
Unified communications: Securing a converged infrastructure
RIM patches serious BlackBerry Attachment Service flaws
Latest Apple iPhone features prompt security concerns
SMS mobile worm attacks Symbian smartphones
Smartphone security lacking at many businesses

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts