Our Network: iPhoneWindows MobileCentroTreo HTCAndroidInstinctPalm Pre
EverythingBerry
Everything Berry BlackBerry Accessory Store BlackBerry Social iPhone forums BlackBerry Wallpapers BlackBerry reviews BlackBerry news


Go Back   BlackBerry Forums > Software > BlackBerry Software

Connect with Facebook





This is a discussion on Vulnerability In ALL BB Handheld OS Current Versions.... within the BlackBerry Software category of our BlackBerry Forums; Be aware that RIM has posted a warning about a vulnerability in the BB Browser in ALL currently used handheld ...
Reply
 
LinkBack Thread Tools Display Modes
Old 09-29-2009, 06:55 PM   #1 (permalink)
Super Moderator
 
stevetaz's Avatar
 
Join Date: Mar 2008
Location: Lonk Island, NY
Posts: 3,832
Thanks: 13
Thanked 118 Times in 98 Posts
Default Vulnerability In ALL BB Handheld OS Current Versions....

Be aware that RIM has posted a warning about a vulnerability in the BB Browser in ALL currently used handheld OS versions. Here is a brief summary:
Overview
This advisory relates to a BlackBerry® Browser dialog box that provides information about web site domain names and their associated certificates. The BlackBerry Browser dialog box informs the BlackBerry device user when there is a mismatch between the site domain name and the domain name indicated in the associated certificate, but does not properly illustrate that the mismatch is due to the presence of some hidden characters (for example, null characters) in the site domain name.

Issue Severity: This vulnerability has a Common Vulnerability Scoring System (CVSS) score of 6.8.

Issue Status: Vulnerability confirmed. Check for software containing the security update based on your wireless service provider. For more information, see the Resolution section.

Recommendation: Complete the resolution actions documented in this advisory.

Mitigation: RIM recommends that BlackBerry device users exercise caution when clicking on links that they receive in email or SMS messages. If a user visits a site that causes a BlackBerry Browser dialog box to warn the user about continuing the connection, the user should select Close connection.


The biggest problem I see is that the updated OS versions RIM has certified solve the issue have not been made available by any of the carriers yet...

Here is the full article and pay attention to what RIM recommends you do until the fix is made available by carriers...

__________________
SteveTaz

If you want a toy, get an iPhone....If you want a tool, get a BlackBerry....

Tact Is For People Who Aren't Witty Enough To Be Sarcastic

"...mercy to the guilty is cruelty to the innocent..."

Adam Smith
The Theory of the Moral Sentiments


Phone: 8330m Curve (Red)
Carrier: Sprint
BB History: New as of 03/19/2008 - 8830 ---> 8330m
stevetaz is offline  
Digg this Post!Share on Facebook!
Reply With Quote
Old 10-14-2009, 05:18 PM   #2 (permalink)
Member
 
Join Date: Feb 2009
Posts: 73
Thanks: 11
Thanked 2 Times in 2 Posts
Default

Thanks for this notice. Just read it now. So it seems the newest at&t OS doesn't fix this, but the newest offical from Mobitel 4.6.0.303 does? Am I interpreting this correctly?

I have actually experienced this malicious message recently.
corvid is offline  
Digg this Post!Share on Facebook!
Reply With Quote
Old 10-14-2009, 05:34 PM   #3 (permalink)
Super Moderator
 
stevetaz's Avatar
 
Join Date: Mar 2008
Location: Lonk Island, NY
Posts: 3,832
Thanks: 13
Thanked 118 Times in 98 Posts
Default

Originally Posted by corvid View Post
Thanks for this notice. Just read it now. So it seems the newest at&t OS doesn't fix this, but the newest offical from Mobitel 4.6.0.303 does? Am I interpreting this correctly?

I have actually experienced this malicious message recently.
I believe you are correct. It appears to me that for the 4.6 OS the .303 update does correct the vulnerability.

When you saw the message did you do anything except close it out and not continue (Close Connection)?
__________________
SteveTaz

If you want a toy, get an iPhone....If you want a tool, get a BlackBerry....

Tact Is For People Who Aren't Witty Enough To Be Sarcastic

"...mercy to the guilty is cruelty to the innocent..."

Adam Smith
The Theory of the Moral Sentiments


Phone: 8330m Curve (Red)
Carrier: Sprint
BB History: New as of 03/19/2008 - 8830 ---> 8330m
stevetaz is offline  
Digg this Post!Share on Facebook!
Reply With Quote
Old 10-14-2009, 05:43 PM   #4 (permalink)
Member
 
Join Date: Feb 2009
Posts: 73
Thanks: 11
Thanked 2 Times in 2 Posts
Default

dang. I can't remember what I did. I also couldn't tell from the article what the ramifications are if you did the wrong thing. But since then I've wiped my device and reinstalled .297.
corvid is offline  
Digg this Post!Share on Facebook!
Reply With Quote
Reply

Bookmarks



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off



All times are GMT -5. The time now is 05:14 AM.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0
Integrated by BBpixel ©2004-2009, jvbPlugin