ID

VAR-200909-0256


CVE

CVE-2009-3477


TITLE

RIM BlackBerry Device Software of Blackberry Browser In any SSL Vulnerability impersonating a server

Trust: 0.8

sources: JVNDB: JVNDB-2009-002699

DESCRIPTION

The Blackberry Browser in RIM BlackBerry Device Software 4.5.0 before 4.5.0.173, 4.6.0 before 4.6.0.303, 4.6.1 before 4.6.1.309, 4.7.0 before 4.7.0.179, and 4.7.1 before 4.7.1.57 does not properly handle "hidden" characters including a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows remote man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. SSL A vulnerability that impersonates a server exists. The problem is CVE-2009-2408 And related issues.An attacker can create any arbitrary certificate through a certificate issued by a regular certificate authority. SSL There is a possibility of impersonating a server. The BlackBerry Device Software browser is prone to a weakness that may cause affected users to trust malicious sites. This issue may potentially lead to other attacks, because users may operate under a false sense of security. This issue affects all versions prior to BlackBerry Device Software 4.5.0.173, 4.6.0.303, 4.6.1.309, 4.7.0.179, and 4.7.1.57. NOTE: This issue affects all built-in browsers installed on BlackBerry devices: BlackBerry Browser Internet Browser WAP Browser Wi-Fi (Hotspot) Browser. ---------------------------------------------------------------------- Do you have VARM strategy implemented? (Vulnerability Assessment Remediation Management) If not, then implement it through the most reliable vulnerability intelligence source on the market. Implement it through Secunia. For more information visit: http://secunia.com/advisories/business_solutions/ Alternatively request a call from a Secunia representative today to discuss how we can help you with our capabilities contact us at: sales@secunia.com ---------------------------------------------------------------------- TITLE: BlackBerry Devices Insufficient Certificate Warning Security Issue SECUNIA ADVISORY ID: SA36875 VERIFY ADVISORY: http://secunia.com/advisories/36875/ DESCRIPTION: A security issue has been reported in BlackBerry Device Software, which can be exploited by malicious people to potentially conduct spoofing attacks. The security issue is caused due to the dialog box displayed by the browser when a mismatched certificate is detected not showing e.g. NULL ('\0') characters. This can be exploited to potentially trick a user into ignoring the warning dialog box and accept a spoofed certificate containing special characters in the Common Name field. PROVIDED AND/OR DISCOVERED BY: The vendor credits Mobile Security Lab and CESG. ORIGINAL ADVISORY: http://www.blackberry.com/btsc/viewContent.do?externalId=KB19552 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 1.98

sources: NVD: CVE-2009-3477 // JVNDB: JVNDB-2009-002699 // BID: 36528 // PACKETSTORM: 81674

AFFECTED PRODUCTS

vendor:rimmodel:blackberry device softwarescope:eqversion:4.7.1

Trust: 1.6

vendor:rimmodel:blackberry device softwarescope:eqversion:4.6

Trust: 1.6

vendor:rimmodel:blackberry device softwarescope:eqversion:4.6.1

Trust: 1.6

vendor:rimmodel:blackberry device softwarescope:eqversion:4.7

Trust: 1.6

vendor:rimmodel:blackberry device softwarescope:eqversion:4.5.0

Trust: 1.6

vendor:blackberrymodel:device softwarescope:eqversion:4.6.1.309

Trust: 0.8

vendor:blackberrymodel:device softwarescope:ltversion:4.7.0

Trust: 0.8

vendor:blackberrymodel:device softwarescope:eqversion:4.7.1.57

Trust: 0.8

vendor:blackberrymodel:device softwarescope:ltversion:4.6.1

Trust: 0.8

vendor:blackberrymodel:device softwarescope:ltversion:4.7.1

Trust: 0.8

vendor:blackberrymodel:device softwarescope:eqversion:4.7.0.179

Trust: 0.8

vendor:blackberrymodel:device softwarescope:ltversion:4.6.0

Trust: 0.8

vendor:blackberrymodel:device softwarescope:eqversion:4.6.0.303

Trust: 0.8

vendor:blackberrymodel:device softwarescope:eqversion:4.5.0.173

Trust: 0.8

vendor:blackberrymodel:device softwarescope:ltversion:4.5.0

Trust: 0.8

vendor:researchmodel:in motion blackberry device softwarescope:eqversion:4.7.1

Trust: 0.3

vendor:researchmodel:in motion blackberry device softwarescope:eqversion:4.7

Trust: 0.3

vendor:researchmodel:in motion blackberry device softwarescope:eqversion:4.6.1

Trust: 0.3

vendor:researchmodel:in motion blackberry device softwarescope:eqversion:4.6

Trust: 0.3

vendor:researchmodel:in motion blackberry device softwarescope:eqversion:4.5

Trust: 0.3

vendor:researchmodel:in motion blackberry device softwarescope:neversion:4.7.1.57

Trust: 0.3

vendor:researchmodel:in motion blackberry device softwarescope:neversion:4.7.179

Trust: 0.3

vendor:researchmodel:in motion blackberry device softwarescope:neversion:4.6.1.309

Trust: 0.3

vendor:researchmodel:in motion blackberry device softwarescope:neversion:4.6.303

Trust: 0.3

vendor:researchmodel:in motion blackberry device softwarescope:neversion:4.5.173

Trust: 0.3

sources: BID: 36528 // JVNDB: JVNDB-2009-002699 // CNNVD: CNNVD-200910-066 // NVD: CVE-2009-3477

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-3477
value: MEDIUM

Trust: 1.0

NVD: CVE-2009-3477
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200910-066
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2009-3477
severity: MEDIUM
baseScore: 6.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.6
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2009-002699 // CNNVD: CNNVD-200910-066 // NVD: CVE-2009-3477

PROBLEMTYPE DATA

problemtype:CWE-310

Trust: 1.8

sources: JVNDB: JVNDB-2009-002699 // NVD: CVE-2009-3477

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200910-066

TYPE

encryption problem

Trust: 0.6

sources: CNNVD: CNNVD-200910-066

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-002699

PATCH

title:KB19552url:http://www.blackberry.com/btsc/viewContent.do?externalId=KB19552

Trust: 0.8

sources: JVNDB: JVNDB-2009-002699

EXTERNAL IDS

db:NVDid:CVE-2009-3477

Trust: 2.4

db:BIDid:36528

Trust: 1.9

db:SECUNIAid:36875

Trust: 1.7

db:SECTRACKid:1022951

Trust: 1.6

db:JVNDBid:JVNDB-2009-002699

Trust: 0.8

db:XFid:53490

Trust: 0.6

db:CNNVDid:CNNVD-200910-066

Trust: 0.6

db:PACKETSTORMid:81674

Trust: 0.1

sources: BID: 36528 // JVNDB: JVNDB-2009-002699 // PACKETSTORM: 81674 // CNNVD: CNNVD-200910-066 // NVD: CVE-2009-3477

REFERENCES

url:http://www.blackberry.com/btsc/viewcontent.do?externalid=kb19552

Trust: 1.7

url:http://www.securitytracker.com/id?1022951

Trust: 1.6

url:http://www.securityfocus.com/bid/36528

Trust: 1.6

url:http://secunia.com/advisories/36875

Trust: 1.6

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/53490

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-3477

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-3477

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/53490

Trust: 0.6

url:http://www.rim.net/

Trust: 0.3

url:http://www.blackberry.com/btsc/dynamickc.do?externalid=kb19552&sliceid=1&command=show&forward=nonthreadedkc&kcid=kb19552

Trust: 0.3

url:http://secunia.com/advisories/36875/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/advisories/business_solutions/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://www.blackberry.com/updates/

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

sources: BID: 36528 // JVNDB: JVNDB-2009-002699 // PACKETSTORM: 81674 // CNNVD: CNNVD-200910-066 // NVD: CVE-2009-3477

CREDITS

Mobile Security Lab and CESG

Trust: 0.9

sources: BID: 36528 // CNNVD: CNNVD-200910-066

SOURCES

db:BIDid:36528
db:JVNDBid:JVNDB-2009-002699
db:PACKETSTORMid:81674
db:CNNVDid:CNNVD-200910-066
db:NVDid:CVE-2009-3477

LAST UPDATE DATE

2025-04-10T23:20:41.617000+00:00


SOURCES UPDATE DATE

db:BIDid:36528date:2009-10-01T16:20:00
db:JVNDBid:JVNDB-2009-002699date:2011-12-22T00:00:00
db:CNNVDid:CNNVD-200910-066date:2009-10-02T00:00:00
db:NVDid:CVE-2009-3477date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:BIDid:36528date:2009-09-28T00:00:00
db:JVNDBid:JVNDB-2009-002699date:2011-12-22T00:00:00
db:PACKETSTORMid:81674date:2009-09-28T05:53:58
db:CNNVDid:CNNVD-200910-066date:2009-09-29T00:00:00
db:NVDid:CVE-2009-3477date:2009-09-29T23:30:00.297