BlackBerry users face security threat

By Joris Evers, CNET News.com
Wednesday, January 04, 2006 11:12 AM

Windows users know that opening a malicious e-mail attachment can wreak havoc on their PC. It appears BlackBerry users have to use caution too.

Opening a malicious image sent via an e-mail on the popular mobile devices could disable a user's capability to view attachments, BlackBerry maker Research In Motion said Tuesday.

The problem occurs because of a software flaw in the BlackBerry Enterprise Server, RIM said in a posting on its customer support Web site. An attacker would have to craft a special TIFF, or Tagged Image File Format, to perform the attack, the company said.

A successful attack would disable only the ability to view attachments; other services such as sending and receiving messages, making phone calls, browsing the Internet, and running BlackBerry wireless device applications to access a corporate network would not be impacted, according to RIM.

RIM has developed a fix for the problem. The software upgrade will be made available as soon as testing is complete, the company said.

While waiting for the update, RIM suggests filtering TIFF images or disabling the attachments on BlackBerrys altogether.

The security vulnerability was discussed at a computer security conference in Berlin last week. US-CERT published an advisory on the problem on Friday.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web