BlackBerry Link < 1.2.3.53 Codec Demux Arbitrary Code Execution

medium Nessus Plugin ID 84987

Synopsis

The remote host has software installed that is affected by an arbitrary code execution vulnerability.

Description

The remote host has a version of BlackBerry Link installed that is prior to version 1.2.3.53. Therefore, it is affected by an arbitrary code execution vulnerability in the codec demux. A remote attacker can exploit this, via crafted MP4 file, to execute arbitrary code.

Solution

Upgrade to BlackBerry Link 1.2.3.53.

See Also

https://salesforce.services.blackberry.com/kbredirect/KB37207

https://us.blackberry.com/software/desktop/blackberry-link

Plugin Details

Severity: Medium

ID: 84987

File Name: blackberry_link_1_2_3_53.nasl

Version: 1.5

Type: local

Agent: windows

Family: Windows

Published: 7/24/2015

Updated: 11/22/2019

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.5

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2015-4111

Vulnerability Information

CPE: cpe:/a:blackberry:blackberry_link

Required KB Items: SMB/blackberry_link/Installed

Exploit Ease: No known exploits are available

Patch Publication Date: 7/14/2015

Vulnerability Publication Date: 7/14/2015

Reference Information

CVE: CVE-2015-4111

BID: 75950