BlackBerry Enterprise Server Router Component Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1015427
|
|
SecurityTracker URL: http://securitytracker.com/id?1015427
|
|
CVE Reference: CVE-2005-2342
(Links to External Site)
|
Date: Dec 31 2005
|
Impact: Denial of service via network
|
Vendor Confirmed: Yes
|
Version(s): BlackBerry Enterprise Server 4.0 and later versions
|
Description: A vulnerability was reported in the BlackBerry Enterprise Server in the BlackBerry Router component. A remote user can cause denial of service conditions.
A remote user with the ability to connect to the target BlackBerry Router component can send specially crafted Server Routing Protocol
(SRP) packets to disrupt communications between the BlackBerry Enterprise Server and the router. This will prevent communications
from BlackBerry devices to the enterprise server.
FX of Phenoelit reported this vulnerability.
|
Impact: A remote user can disrupt communications between BlackBerry devices and the BlackBerry Enterprise Server.
|
Solution: No solution was available at the time of this entry.
The vendor is working on a fix.
The vendor's advisory is available at:
http://www.blackberry.com/knowledgecen
terpublic/livelink.exe/fetch/2000/8021/728075/728850/728215/?nodeid=1167898
|
Vendor URL: www.blackberry.com/ (Links to External Site)
|
Cause: Exception handling error
|
|
Message History:
None.
|
Source Message Contents
|
Date: Fri, 30 Dec 2005 23:49:50 -0500
Subject: Known Issues - Denial of service on the BlackBerry Router
|
http://www.blackberry.com/knowledgecenterpublic/livelink.exe/fetch/2000/8021/728075/728850/728215/?no deid=1167898
CVE-2005-2342
|
|