First published: Tue Oct 05 2010(Updated: )
The offline backup mechanism in Research In Motion (RIM) BlackBerry Desktop Software uses single-iteration PBKDF2, which makes it easier for local users to decrypt a .ipd file via a brute-force attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry Desktop Software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3741 has a medium severity rating due to the potential for brute-force decryption of backup files.
Fixing CVE-2010-3741 involves updating the RIM BlackBerry Desktop Software to a version that employs stronger key derivation functions.
CVE-2010-3741 exposes users to brute-force attacks that can compromise the security of offline backups.
CVE-2010-3741 specifically affects .ipd files created through the RIM BlackBerry Desktop Software.
Yes, local users can exploit CVE-2010-3741 to decrypt backup files due to the weak encryption method used.