Internet Telephony Product of the Year

Blackberry™ 7270 SIP stack transaction processing vulnerability

Advisory Number: VIPER-2007-025
Release Date: 2007.03.26
Source: Sipera VIPER Lab
Systems Affected: Blackberry 7270- Wireless Handheld (OS v4.0.1.83, Platform 1.0.0.69)
Category: Mobile Device Denial of Service
Severity: Medium

Overview

A vulnerability in Blackberry 7270 SIP stack while processing transaction state after the user picks up the call may allow an attacker to control call disconnection.

Impact

The phone remains unavailable for approximately 40 seconds after processing such INVITE. No calls can be made or received during the duration.

Description

Attacker can use a script to send a malicious INVITE message to Blackberry 7270 and disable call disconnection for approximately 40 seconds. During this duration attempt to make a call from the 7270 results in error-- “Cannot connect. Call in progress”. Additionally, attempt to make a call to the phone results in 486 Busy Here response from the phone.

Solution

Phone SIP stack implementation should be patched to prevent exploiting such vulnerability.

Vendor Response:

RIM: A vulnerability exists in the Session Initiation Protocol (SIP) implementation on WLAN BlackBerry 7270 smartphones with BlackBerry Device Software Version 4.0.1.83 and earlier that if exploited by an attacker can result in a temporary Denial of Service in the phone application, but does not affect the other capabilities of the smartphone. This does not affect any other BlackBerry models. To exploit this vulnerability, a user with malicious intent requires access to a private branch exchange (PBX) from within the enterprise network. Research In Motion is working to provide a patch for this issue in a timely manner. For more information please see http://www.blackberry.com/security/news.jsp

For more information on any of these threat advisories, please email Sipera VIPER Lab at viper@sipera.com

Unified Communications Unleashed
Sipera Systems is the worldwide market leader in solutions for the rapid and simple adoption of Unified Communications (UC). Thousands of users around the globe rely on Sipera to secure VoIP, IP video, collaboration, messaging and dozens of other high-performance applications. Sipera’s groundbreaking “Borderless UC” enables controlled communications to any device in any location.

Years of UC Security experience is contained in Sipera unified communications (UC-Sec) products. These appliances benefit from the research conducted by Sipera VIPER Lab to provide comprehensive threat protection, policy enforcement, access control, and privacy in a single, real-time appliance.

© Copyright 2006-2010 Sipera Systems, Inc. All rights reserved. Sipera, Sipera UC-Sec and related products, Sipera LAVA and Sipera VIPER and related services are trademarks of Sipera Systems, Inc.