First published: Wed Oct 25 2006(Updated: )
Research in Motion (RIM) BlackBerry Enterprise Server 4.1 SP2 before Hotfix 1 for IBM Lotus Domino might allow attackers with meeting organizer privileges to cause a denial of service (application hang) via a deleted recurrent meeting instance when changing the attendee's calendar meeting time.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry Enterprise Server | <=4.1_sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5489 has been reported to potentially cause denial of service due to application hang.
To fix CVE-2006-5489, update to BlackBerry Enterprise Server 4.1 SP2 Hotfix 1 or a later version.
CVE-2006-5489 affects users of BlackBerry Enterprise Server 4.1 SP2 prior to Hotfix 1 when using IBM Lotus Domino.
CVE-2006-5489 allows attackers with meeting organizer privileges to delete a recurrent meeting instance which may hang the application.
If you cannot update due to CVE-2006-5489, consider restricting meeting organizer privileges until a patch can be applied.