Title: Blackberry Handheld JAD File Browser Denial Of Service Vulnerability
Severity: MODERATE
Description:
Blackberry Handheld devices are prone to a denial of service attack. The embedded Web browser will stop responding due to a dialog box that has not been properly dismissed when handling a malformed JAD (Java Application Description) file.
The vulnerability is caused when the user of the device downloads a malformed JAD file from a Web site. The JAD file will specify a long application name and vendor string of 256 bytes or more.
This issue affects device running Blackberry Device Software versions prior to 4.0.2.
Affected Products:
- Research In Motion Blackberry 7100g 0.0.0
- Research In Motion Blackberry 7100i 0.0.0
- Research In Motion Blackberry 7100r 0.0.0
- Research In Motion Blackberry 7100t 0.0.0
- Research In Motion Blackberry 7100v 0.0.0
- Research In Motion Blackberry 7100x 0.0.0
- Research In Motion Blackberry 7105t 0.0.0
- Research In Motion Blackberry 7130e 0.0.0
- Research In Motion Blackberry 7230 3.7.1.41
- Research In Motion Blackberry 7230 3.8.0
- Research In Motion Blackberry 7230 4.0.0
- Research In Motion Blackberry 7250 0.0.0
- Research In Motion Blackberry 7280 0.0.0
- Research In Motion Blackberry 7290 0.0.0
- Research In Motion Blackberry 7520 0.0.0
- Research In Motion Blackberry 7730 0.0.0
- Research In Motion Blackberry 7750 0.0.0
- Research In Motion Blackberry 7780 0.0.0
- Research In Motion Blackberry 8700c 0.0.0
- Research In Motion Blackberry 8700f 0.0.0
- Research In Motion Blackberry 8700r 0.0.0
- Research In Motion Blackberry Desktop Manager
- Research In Motion Blackberry Device Software 4.0.0
References:
- Research In Motion: Support - Browser dialogue box not properly dismissed after downloading a corrup
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.