[HV-MED] UPDATE: RIM Blackberry DoS, data loss

vuln_at_hexview.com
Date: 10/14/04

  • Next message: Marc Deslauriers: "[FLSA-2004:1737] Updated httpd packages fix a mod_proxy security vulnerability"
    Date: Thu, 14 Oct 2004 11:08:29 -0700
    To: bugtraq@securityfocus.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    UPDATE: RIM Blackberry DoS, data loss

    Original disclosure is available at http://www.hexview.com/docs/20041012-1.txt

    Classification:
    ===============
    Level: low-[MED]-high-crit
    ID: HEXVIEW*2004*10*14*1
    URL: http://www.hexview.com/docs/20041014-1.txt

    Update summary:
    ===============
    Vulnerability level changed to MEDIUM.
    Vulnerability description is updated.
    Vendor status is updated.
    HexView disclosure policy is updated.

    Vulnerability update:
    =====================
    There is no buffer overflow condition. Device reset is triggered by a watchdog timer
    that times out when a long message is being stored in flash memory. Since reset
    is triggered in the middle of write process, it may cause unpredictable results,
    but in most cases the data does not get corrupted. HexView confirms that there was
    a data corruption issue during tests, but it was not possible to reproduce it.

    Vendor Status:
    ==============
    Vendor has produced a fix for the vulnerability.

    About HexView:
    ==============
    HexView contributes to online security-related lists for almost a decade.
    The scope of our expertize spreads over Windows, Linux, Sun, MacOS platforms,
    network applications, and embedded devices. The chances are you read our
    advisories or disclosures. For more information visit http://www.hexview.com

    Distribution:
    =============
    This document may be freely distributed through any channels as long as the
    contents are kept unmodified. Commercial use of the information in the document
    is not allowed without written permission from HexView signed by our pgp key.

    HexView Disclosure Policy:
    ==========================
    HexView notifies vendors that have publicly available contact e-mail
    24 hours before disclosing any information to the public. If we are unable
    to find vendor's e-mail address or if no reply is received within 24 hours,
    HexView will publish vulnerability notification including all technical
    details unless the issue is rated as "critical". If vendor does not reply
    within 72 hours, HexView may disclose all details for critical vulnerabilities
    as well.

    If vendor replies within the above mentioned time period, HexView will
    announce the vulnerability, but will not disclose the details required to
    reproduce it. HexView will also specify the date when full disclosure
    containing all the details will be published. The time period between
    announcement and full disclosure is 30 days unless there is an agreement
    with vendor and appropriate justification for extension. If vendor resolves
    the issue earlier than 30 days after announcement, HexView will publish full
    disclosure as soon as the fix is available to the public.

    HexView also reserves the right to publish any detail of any vulnerability
    at any time.

    Feedback and comments:
    ======================
    Feedback and questions about this disclosure are welcome at vtalk@hexview.com

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.5 (GNU/Linux)

    iD8DBQFBbr6lDPV1+KQrDqQRArfsAJ9LetHLRF5zvJkEejIU3QJp6QjhmACgj/Yj
    1ozDg5ejkW3Fyc6W4cwAWlU=
    =heGu
    -----END PGP SIGNATURE-----


  • Next message: Marc Deslauriers: "[FLSA-2004:1737] Updated httpd packages fix a mod_proxy security vulnerability"

    Relevant Pages

    • [HV-MED] Zip/Linux long path buffer overflow
      ... HexView tested the issue using Zip 2.3 which comes as "zip" package ... It is possible to exploit this vulnerability by embedding a shellcode ... HexView tried to notify vendor using vendor-provided e-mail address ... HexView will also specify the date when full disclosure ...
      (Bugtraq)
    • [Full-Disclosure] [HV-MED] Zip/Linux long path buffer overflow
      ... HexView tested the issue using Zip 2.3 which comes as "zip" package ... It is possible to exploit this vulnerability by embedding a shellcode ... HexView tried to notify vendor using vendor-provided e-mail address ... HexView will also specify the date when full disclosure ...
      (Full-Disclosure)
    • [HV-MED] Zip/Linux long path buffer overflow
      ... HexView tested the issue using Zip 2.3 which comes as "zip" package ... It is possible to exploit this vulnerability by embedding a shellcode ... HexView tried to notify vendor using vendor-provided e-mail address ... HexView will also specify the date when full disclosure ...
      (Full-Disclosure)
    • [Full-Disclosure] [HV-MED] Zip/Linux long path buffer overflow
      ... HexView tested the issue using Zip 2.3 which comes as "zip" package ... It is possible to exploit this vulnerability by embedding a shellcode ... HexView tried to notify vendor using vendor-provided e-mail address ... HexView will also specify the date when full disclosure ...
      (Full-Disclosure)
    • Re: Using 0days as part of pen-test?
      ... the client the option to determine how the vendor gets notified. ... vulnerability information you discover during ... The legal issue isn't the disclosure process, you can act as "legal entity" ... security threats until the vendor release a patch. ...
      (Pen-Test)