The Research in Motion BlackBerry 7270 before 4.0 SP1 Bundle 108 does not properly manage transaction states, which allows remote attackers to cause a denial of service (temporary device hang) by sending a certain SIP INVITE message, but not providing an ACK when the call is answered.
Link | Tags |
---|---|
http://www.blackberry.com/btsc/articles/220/KB12705_f.SAL_Public.html | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35075 | vdb entry |
http://osvdb.org/37647 | vdb entry |
http://www.kb.cert.org/vuls/id/324841 | third party advisory us government resource |
http://secunia.com/advisories/25824 | third party advisory |
http://www.sipera.com/index.php?action=resources%2Cthreat_advisory&tid=213& | |
http://www.securityfocus.com/bid/24545 | vdb entry |