BlackBerry Desktop Software Lotus Notes Intellisync Arbitrary Code Execution

ERCOLINO

Membro dello Staff
Amministratore
Registrato
3 Marzo 2003
Messaggi
256.014
Località
Torino
Secunia Advisory: SA37244
Release Date: 2009-11-04


Critical:Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

Software:
BlackBerry Desktop Software 3.x
BlackBerry Desktop Software 4.x
BlackBerry Desktop Software 5.x


Description:
A vulnerability has been reported in BlackBerry Desktop Software, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an unspecified error in the Lotus Notes Intellisync component (lnsresobject.dll). This can be exploited to potentially execute arbitrary code by tricking a user into visiting a malicious website.

The vulnerability is reported in versions prior to 5.0.1


Solution:
Update to version 5.0.1:

https://www.blackberry.com/Downloads/...code=A8BAA56554F96369AB93E4F3BB068C22


Bollettino Sicurezza
 
Indietro
Alto Basso