12 Aug 2011
RIM has warned of several high severity vulnerabilities in its enterprise software which could allow attackers to gain access to and execute code on the BlackBerry Enterprise Server.
The company revealed in a security advisory that the flaws relate to the way the BlackBerry MDS Connection Service and the BlackBerry Messaging Agent process PNG and TIFF images for rendering on the firm's smartphones.
An attacker would have to entice a user to a specially crafted web page or embed specially crafted PNG and TIFF images in an email to exploit the vulnerability, which has been given a Common Vulnerability Scoring System rating of 10.0, meaning high severity.
RIM urged all users to install the relevant security update on any computer which hosts a BlackBerry MDS Connection Service or BlackBerry Messaging Agent instance.
"These updates replace the installed image.dll file that the affected components use with an image.dll file that is not affected by the vulnerabilities," the firm said.
Sophos senior technology consultant Graham Cluley warned that, by exploiting the flaws, hackers may be able to plant malicious code on a user's BlackBerry Enterprise Server which "opens up a back door for remote access".
"Depending on how your network infrastructure is set up, intruders might be able to see into other parts of your network and steal information," he added.
"Alternatively, the hackers' code might cause your systems to crash, perhaps interrupting communications."
The news comes just one day after security researchers at NGS Secure found potential security problems with RIM's PlayBook tablet.
Latest stories from Security
Related articles
Related jobs
Poll
Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?
TFL director of Games transport Mark Evers discusses how the public transport network is preparing for this summer's event
Connect with V3.co.uk
The wrong printers, for the wrong tasks on the wrong contracts
Who leads the BI pack and who should we be watching out for?
Functional Oracle Support Analyst - EBS Financials, Support...
Oracle E-Business Suite Technical Consultant - EBS...
Oracle Applications DBA - East London - All salaries...
Oracle Functional Consultants - Financial - Project Accounting...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?