>> BlackBerry Enterprise Server PNG Handling Buffer Overflow Vulnerability
Title : BlackBerry Enterprise Server PNG Handling Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2006-0127 CVE ID : CVE-2005-2344
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-01-10
Technical Description
A vulnerability has been identified in BlackBerry Enterprise Server, which may be exploited by remote attackers to execute arbitrary code. This flaw is due to a heap overflow error in the BlackBerry Attachment Service that does not properly handle malformed PNG image attachments, which could be exploited by an unauthenticated remote attacker to crash or compromise a vulnerable server via a malicious Portable Network Graphics (PNG) file.