ID

VAR-201203-0466


TITLE

Blackberry WebKit Browser Engine Remote Code Execution Vulnerability

Trust: 0.9

sources: CNVD: CNVD-2012-1049 // BID: 52288

DESCRIPTION

The BlackBerry PlayBook Tablet is a tablet from BlackBerry. BlackBerry smartphones are smart phone devices from BlackBerry. The open source webkit browser engine used by BlackBerry 6, BlackBerry 7, BlackBerry 7.1 and BlackBerry PlayBook tablet has security vulnerabilities. Attackers can build malicious web pages to entice users to access arbitrary code. For BlackBerry phone devices, an attacker can read and write data from a BlackBerry phone memory card, but not some user data stored in the application, such as email, calendar, and contacts. On the BlackBerry PlayBook tablet, an attacker can execute arbitrary code in context on the browser. An attacker can exploit this issue by tricking an unsuspecting victim into viewing a webpage containing malicious content

Trust: 0.81

sources: CNVD: CNVD-2012-1049 // BID: 52288

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2012-1049

AFFECTED PRODUCTS

vendor:researchmodel:in motion blackberry device softwarescope:eqversion:6.0

Trust: 0.9

vendor:researchmodel:in motion blackberry device softwarescope:eqversion:7.1

Trust: 0.9

vendor:researchmodel:in motion blackberry device softwarescope:eqversion:7

Trust: 0.9

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.5.2304

Trust: 0.9

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.5.2342

Trust: 0.9

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.6

Trust: 0.9

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.7.2942

Trust: 0.9

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.7.3312

Trust: 0.9

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:2.0.0.7971

Trust: 0.9

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.8.6067

Trust: 0.9

vendor:researchmodel:in motion blackberry playbook tablet softwarescope:eqversion:1.0.8.4985

Trust: 0.9

sources: CNVD: CNVD-2012-1049 // BID: 52288

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201203-061

TYPE

Design Error

Trust: 0.3

sources: BID: 52288

PATCH

title:Blackberry WebKit Browser Engine Remote Code Execution Vulnerability Patchurl:https://www.cnvd.org.cn/patchinfo/show/12151

Trust: 0.6

sources: CNVD: CNVD-2012-1049

EXTERNAL IDS

db:BIDid:52288

Trust: 1.5

db:CNVDid:CNVD-2012-1049

Trust: 0.6

db:CNNVDid:CNNVD-201203-061

Trust: 0.6

sources: CNVD: CNVD-2012-1049 // BID: 52288 // CNNVD: CNNVD-201203-061

REFERENCES

url:http://btsc.webapps.blackberry.com/btsc/microsites/microsite.do?cmd=displaykc

Trust: 0.6

url:http://www.securityfocus.com/bid/52288

Trust: 0.6

url:http://btsc.webapps.blackberry.com/btsc/microsites/microsite.do?cmd=displaykc&doctype=kc&externalid=kb30152&sliceid=1&doctypeid=dt_security_1_1

Trust: 0.3

url:http://www.rim.net/

Trust: 0.3

sources: CNVD: CNVD-2012-1049 // BID: 52288 // CNNVD: CNNVD-201203-061

CREDITS

This issue is disclosed in RSA Security Conference.

Trust: 0.9

sources: BID: 52288 // CNNVD: CNNVD-201203-061

SOURCES

db:CNVDid:CNVD-2012-1049
db:BIDid:52288
db:CNNVDid:CNNVD-201203-061

LAST UPDATE DATE

2022-05-17T01:37:43.824000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2012-1049date:2012-03-07T00:00:00
db:BIDid:52288date:2012-03-05T00:00:00
db:CNNVDid:CNNVD-201203-061date:2012-03-07T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2012-1049date:2012-03-07T00:00:00
db:BIDid:52288date:2012-03-05T00:00:00
db:CNNVDid:CNNVD-201203-061date:2012-03-07T00:00:00