First published: Sat Dec 31 2005(Updated: )
The BlackBerry Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.0 to version 4.0 Service Pack 2 allows attackers to cause a denial of service via a malformed Portable Network Graphics (PNG) file that triggers a heap-based buffer overflow.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry Enterprise Server | =4.0 | |
BlackBerry Enterprise Server | =4.0_sp1 | |
BlackBerry Enterprise Server | =4.0_sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2344 is classified as a high severity vulnerability due to its potential to cause a denial of service.
To mitigate CVE-2005-2344, it's recommended to upgrade the BlackBerry Enterprise Server to a patched version beyond 4.0 Service Pack 2.
CVE-2005-2344 affects BlackBerry Enterprise Server versions 4.0, 4.0 Service Pack 1, and 4.0 Service Pack 2.
CVE-2005-2344 is a heap-based buffer overflow vulnerability triggered by malformed PNG files.
Yes, CVE-2005-2344 can be exploited remotely to disrupt the BlackBerry Attachment Service.