CVE-2013-6798: Medium severity BlackBerry BlackBerry Link vulnerability
BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not properly determine the user account for execution of Peer Manager in certain situations involving successive logins with different accounts, which allows context-dependent attackers to bypass intended restrictions on remote file-access folders via IPv6 WebDAV requests, a different vulnerability than CVE-2013-3694.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BlackBerry Linkto a version that resolves this vulnerability.Fixed in 1.2.1.31 - Upgrade
Upgrade
BlackBerry Link (Mac OS X)to a version that resolves this vulnerability.Fixed in 1.1.1 build 39
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6798?
CVE-2013-6798 has a medium severity rating due to its ability to allow context-dependent attackers to bypass intended restrictions.
How do I fix CVE-2013-6798?
To fix CVE-2013-6798, update BlackBerry Link to version 1.2.1.31 or later on Windows or version 1.1.1 build 39 or later on Mac OS X.
What systems are affected by CVE-2013-6798?
CVE-2013-6798 affects various versions of BlackBerry Link on Windows and Mac OS X.
What can attackers do with CVE-2013-6798?
Attackers can potentially bypass account restrictions within BlackBerry Link due to improper user account determination.
When was CVE-2013-6798 discovered?
CVE-2013-6798 was reported on December 30, 2013.