Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT Security Bulletin ASB-2009.1099.2 BlackBerry Device Software Updated 30 September 2009 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: BlackBerry Device Operating System: Mobile Devices Impact/Access: Provide Misleading Information -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2009-3477 Member content until: Thursday, October 29 2009 Revision History: September 30 2009: Added CVE Reference September 29 2009: Initial Release OVERVIEW BlackBerry have released an update for the BlackBerry Device Software correcting a security vulnerability. IMPACT The vendor has provided the following information regarding this vulnerability: "A malicious user could create a web site that includes a certificate that is purposely altered using null (hidden) characters in the certificate's Common Name (CN) field or otherwise manipulated to deceive a BlackBerry device user into believing they have connected to a trusted web site. If the malicious user then performs a phishing-style attack by sending the BlackBerry device user a link to the web site in an SMS or email message that appears to be from a trusted source, and the BlackBerry device user chooses to access that site, the BlackBerry Browser will correctly detect the mismatch between the certificate and the domain name and display a dialog box that prompts the user to close the connection. However, the dialog box does not display null characters, so the user may believe they are connecting to a trusted site and disregard the recommended action to close the connection."[1] MITIGATION This vulnerability has been corrected in the following versions [1]: BlackBerry Device Software Version 4.5.0.173 or later BlackBerry Device Software Version 4.6.0.303 or later BlackBerry Device Software Version 4.6.1.309 or later BlackBerry Device Software Version 4.7.0.179 or later BlackBerry Device Software Version 4.7.1.57 or later REFERENCES [1] BlackBerry Browser dialog box does not clearly indicate mismatches between web site domain names and associated certificates http://www.blackberry.com/btsc/search.do?cmd=displayKC&docType=kc&externalId=KB19552 AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. If you believe that your computer system has been compromised or attacked in any way, we encourage you to let us know by completing the secure National IT Incident Reporting Form at: http://www.auscert.org.au/render.html?it=3192 =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iD8DBQFKwrmWNVH5XJJInbgRAgmWAJ4/u4pfYMOAHVad94rHzkPO8RswqQCcD0ZM KqiRNic12fhaaioKOvNwj9w= =s/5V -----END PGP SIGNATURE-----