Serious Security Issue with Blackberry Servers
The BlackBerry system is vulnerable: The manufacturer warns that criminals could gain over specially prepared photos or websites to access the servers of corporate clients and install their programs. An update will fix the problem. The manufacturer of the Blackberry smartphone, Research In Motion (RIM), warned of a vulnerability . Certain versions of its Blackberry Enterprise software have a vulnerability in the highest hazard level, the company reports on its support site. The Blackberry phones themselves are not affected by the problem, nor does the Desktop software or the Internet services of the company.
But even if they are not directly affected, can Blackberry smartphones due to the vulnerability be exploited as an entry point for malicious programs in the enterprise software company. Users of affected systems are generally companies that manufacture their own server with Blackberry software encrypted connections between internal applications and the BlackBerrys of staff.
This actually a very safe current combination may be compromised in an insidious way, according to RIM. Therefore has a Blackberry software, the image files on the server for Blackberry smartphones processed, a vulnerability. Depending on how the network is built there and how the user rights are distributed to unauthorized attackers could gain access to many parts of the network and install their own programs and run them.
Click unnecessary
There are two possibilities for criminals to trick users to break into the system. The complex is to provide a site on the web, on a specially prepared image is stored that the required malicious code in it. Blackberry users might be misled by bogus e-mails or instant messages them to click a link to this since then, which indicates the software would be installed.
However, it is much easier to send the victim to an e-mail, in a suitably prepared image is embedded. In such a case would have affected the e-mail does not even have to open to cause an infestation of the server with malicious software. This would be done almost automatically, when the Blackberry server processed the image in such a mail for further delivery to the recipient.
As an immediate measure, declared the Blackberry support, you could disable the processing of image files from the server. But that was only a last resort. Safer it is to close the security gap by update. Appropriate update packages, the company provided online. With the publication of the warning they had waited until the patches were available.
How long was the weak point or how long it is known, the company has given no information.

