First published: Wed Jun 27 2007(Updated: )
Format string vulnerability on the Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 allows remote attackers to cause a denial of service (blocked call reception and calling) via format string specifiers in an SIP INVITE message that lacks a host name in the Contact header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry 7270 | <=4.0_sp1_bundle_83 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3442 has a medium severity level due to its potential to cause a denial of service.
To fix CVE-2007-3442, upgrade the BlackBerry 7270 to version 4.0 SP1 Bundle 108 or later.
CVE-2007-3442 represents a denial of service attack via format string vulnerabilities in SIP INVITE messages.
CVE-2007-3442 affects the BlackBerry 7270 devices running versions prior to 4.0 SP1 Bundle 108.
CVE-2007-3442 primarily causes service disruption rather than data exposure.