CERT-In Vulnerability Note
CIVN-2009-0140
BlackBerry Desktop Software Lotus Notes Intellisync Arbitrary Code Execution Vulnerability
Original Issue Date:November 16, 2009
Severity Rating: HIGH
Systems Affected
BlackBerry Desktop Software version 5.0 and prior
Overview
A vulnerability has been reported in BlackBerry Desktop Software, which could be exploited by remote attackers to compromise an affected system.
Description
Research In Motion BlackBerry Desktop Manager is used to synchronize smart phones and desktop computers.
This vulnerability is caused by a buffer overflow error in the Lotus Notes Intellisync ActiveX control lnsresobject.dll , when processing user-supplied data. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code by tricking a user into visiting a specially crafted web page. Failed attacks could result in Denial of Service conditions DoS .
Solution
Upgrade to BlackBerry Desktop Software version 5.0.1 or later
https://www.blackberry.com/Downloads/entry.do?code=A8BAA56554F96369AB93E4F3BB068C22
Vendor Information
RIM BlackBerry
http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB19701
References
RIM BlackBerry
http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB19701
VUPEN
http://www.vupen.com/english/advisories/2009/3133/
Secunia
http://secunia.com/advisories/37244/
SecurityFocus
http://www.securityfocus.com/bid/36903/
Security Lab
http://en.securitylab.ru/nvd/387307.php
CVE Name
CVE-2009-0306
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|