BlackBerry patches vulnerabilities in BlackBerry OS, enterprise server software

BlackBerry patches vulnerabilities in BlackBerry OS, enterprise server software

تاریخ ایجاد

Number: IRCNE2014082291
Date: 2014-08-16

According to “computerwprld”, BlackBerry's focus on strong security as a key differentiator for its devices does not mean that they're completely free of flaws. The company released security updates Tuesday for both the OS running on its smartphones and for its enterprise server software.
BlackBerry OS version 10.2.1.1925 was released for the company's Z10, Z30, Q10 and Q5 phone models. It fixes an authentication bypass vulnerability that could allow attackers connected to the same wireless network as affected devices to read or modify data stored on them.
The flaw can only be exploited on devices that have the Wi-Fi file-sharing service running, a service that's not enabled by default.
"Using a password for file sharing is not a workaround for this vulnerability," BlackBerry said in a security advisory published Tuesday.
The company also released BlackBerry Enterprise Service version 10.2.2 and BlackBerry Enterprise Server version 5.0.4 MR7 to fix an information disclosure vulnerability that in certain cases could allow attackers to gain access to credentials stored in the server's diagnostic logs.
"During rare cases of an exception, certain credentials are logged in an encoded form or in plain text," BlackBerry said in an advisory.
A workaround for this vulnerability is to manually delete the logs or to redact the sensitive information stored in them.

برچسب‌ها