BlackBerry Browser Address Parsing Denial Of Service Vulnerability
21 Apr. 2012
Summary
A Denial of Service (DoS) issue exists in the BlackBerry Browser in BlackBerry Device Software version 4.2 and earlier. Research In Motion (RIM) has corrected this problem in later releases of the BlackBerry Device Software. While in the process of parsing a long web page address, the BlackBerry Browser uses almost all of the BlackBerry device processing capability. This may cause the BlackBerry device to become slow or to stop responding.
Credit:
The information has been provided by Michael Kemp .
Vulnerable Systems:
* BlackBerry devices
* BlackBerry Device Software version 4.2 and earlier
A web site creator with malicious intent may use a Hypertext Markup Language (HTML) or Wireless Markup Language (WML) web page that contains a long string value within the link. If the BlackBerry device user accesses the link using the BlackBerry Browser, a temporary DoS may occur and the BlackBerry device may stop responding.
Vendor Status:
Blackberry had issued a security update for this vulnerability