Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • PM Modi in Manipur
  • Charlie Kirk killer
  • Sushila Karki
  • IND vs PAK
  • India-US ties
  • New human organ
  • Downton Abbey: The Grand Finale Movie Review
fp-logo
Vulnerability in BlackBerry MDS Connection Service could allow remote code execution
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • Vulnerability in BlackBerry MDS Connection Service could allow remote code execution

Vulnerability in BlackBerry MDS Connection Service could allow remote code execution

Anuradha Shetty • February 19, 2013, 16:47:47 IST
Whatsapp Facebook Twitter

A recent post on BlackBerry website highlights that vulnerabilities have been detected in the way….

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Vulnerability in BlackBerry MDS Connection Service could allow remote code execution

A recent post on BlackBerry website highlights that vulnerabilities have been detected in the way the BlackBerry MDS Connection Service and the BlackBerry Messaging Agent process TIFF images for rendering on the BlackBerry smartphone. 

Armed with a Common Vulnerability Scoring System (CVSS) score of 10.0 (high severity), what makes these vulnerabilities a cause of worry is, if successful, it may allow an attacker to win access and then execute a code on the BlackBerry Enterprise Server. It doesn’t end there. Based on the available priveleges to the configured BlackBerry Enterprise Server service account, the miscreant may even be able to extend his reach to other non-segmented parts of the network.

STORY CONTINUES BELOW THIS AD

To exploit the vulnerabilities present in the way TIFF images are processed by BlackBerry MDS Connection Service, an attacker would have to make a special webpage – adept to convince a user to clock on the link to that webpage. The link in question would be given to the user by way of an email or instant message. 

More from News & Analysis
What is the US HIRE Bill and why is India’s $250-billion IT sector worried? What is the US HIRE Bill and why is India’s $250-billion IT sector worried? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true? Is the internet dead? What's this theory that OpenAI's Sam Altman says might be true?

addd

Provides interim security update

The post adds, “RIM is not aware of any attacks on or specifically targeting BlackBerry Enterprise Server customers, and recommends that affected customers update to the latest available software version to be fully protected from these vulnerabilities.”

What’s more, to make good of these vulnerabilities in the way the BlackBerry Messaging Agent or the BlackBerry Collaboration Service processes TIFF images, the attacker would have to embed that questionable TIFF image in an email or enterprise instant message and send the message to the BlackBerry smartphone user. Shockingly, the user does not have to click a link or an image, or even view the mail or IM for the attack to go through. 

The company, however, has issued BlackBerry Enterprise Server version 5.0.4 MR2, which it says fixes these holes and can be used for all affected supported versions of BlackBerry Enterprise Server. The company has also issued an interim security update that it states is verified with supported versions of BlackBerry Enterprise Server and BlackBerry Enterprise Server Express. 

The interim security update essentially replaces the installed image.dll file, which the affected components use, with an image.dll file that is not affected by the vulnerabilities.

List of affected software:

  • BlackBerry Enterprise Server Express version 5.0.4 and earlier for Microsoft Exchange and IBM Lotus Domino
  • BlackBerry Enterprise Server version 5.0.4 and earlier for Microsoft Exchange, IBM Lotus Domino and Novell Groupwise

List of non-affected software:

  • BlackBerry Device Software
  • BlackBerry Desktop Software
  • BlackBerry Enterprise Server version 5.0.4 MR1 and later for Microsoft Exchange, IBM Lotus Domino and Novell Groupwise
  • BlackBerry Enterprise Server Express version 5.0.4 (interim security update) and later for Microsoft Exchange and IBM Lotus Domino
  • BlackBerry Enterprise Service 10
Tags
BlackBerry BlackBerry Enterprise Server General Microsoft Exchange
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

Russian drones over Poland: Trump’s tepid reaction a wake-up call for Nato?

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

As Russia pushes east, Ukraine faces mounting pressure to defend its heartland

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Why Mossad was not on board with Israel’s strike on Hamas in Qatar

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Turkey: Erdogan's police arrest opposition mayor Hasan Mutlu, dozens officials in corruption probe

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV