BlackBerry security hole patched

Share this article:

A security hole in the Windows software used to download files to BlackBerry phones has been plugged.

BlackBerry maker Research In Motion (RIM) on Wednesday addressed a vulnerability in its BlackBerry Application Web Loader, an ActiveX control that is typically started on a web page and downloads software through a USB cable connected to the phone.

RIM issued an advisory that said: “When a BlackBerry device user browses to a website that is designed to install the BlackBerry Application Web Loader ActiveX control on BlackBerry devices over a USB connection, and clicks ‘Yes' to install and run the ActiveX control, the ActiveX control introduces the vulnerability [a buffer overflow] to the computer.”

The RIM advisory said that the vulnerability has a Common Vulnerability Scoring System (CVSS) score of 9.3. CVSS scores range from 0 (no vulnerability) to 10 (critical).

“By convincing a user to view a specially crafted HTML document, an attacker may be able to execute arbitrary code with the privileges of the user," a US-CERT alert warned. "The attacker could also cause Internet Explorer to crash."

For its part, Microsoft addressed the problem in a revised patch released Tuesday, saying in an advisory that one of its latest security updates sets a kill bit for an ActiveX control developed by RIM. A kill bit stops an ActiveX control from running in Internet Explorer.

Users can get a new version of the BlackBerry Application Web Loader (version 1.1) here.

Share this article:
You must be a registered member of SC Magazine to post a comment.
close

Next Article in News

Sign up to our newsletters

TOP COMMENTS

More in News

Information sharing requires breaking down barriers, White House cyber guru says

Information sharing requires breaking down barriers, White House ...

The White House has advanced an agenda to promote and facilitate information sharing on security threats and vulnerabilities.

Worm variant of Android ransomware, Koler, spreads via SMS

Worm variant of Android ransomware, Koler, spreads via ...

Upon infection, the Koler variant will send an SMS message to all contacts in the device's address book.

Patch for Windows flaw can be bypassed, prompts temporary fix from Microsoft

Patch for Windows flaw can be bypassed, prompts ...

The Windows zero-day received a patch last week, but the fix can still be bypassed by crafty attackers.