First published: Wed Jun 27 2007(Updated: )
The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allows remote attackers to cause a denial of service (temporary device hang) by sending a certain SIP INVITE message, but not providing an ACK when the call is answered.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry 7270 | <=4.0_sp1_bundle_83 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3443 has a moderate severity rating due to its ability to cause denial of service on affected BlackBerry devices.
To fix CVE-2007-3443, upgrade your BlackBerry 7270 to version 4.0 SP1 Bundle 108 or later.
CVE-2007-3443 specifically affects the BlackBerry 7270 running versions prior to 4.0 SP1 Bundle 108.
CVE-2007-3443 involves a denial of service attack that can be triggered by sending a specific SIP INVITE message to the device.
Exploitation of CVE-2007-3443 can lead to a temporary device hang, causing it to become unresponsive.