Welcome, Guest

Nortel Response to OpenSSL DTLS Heap Buffer Overflow Vulnerability

Description: OpenSSL is prone to a heap buffer-overflow vulnerability because the library fails to perform adequate boundary checks on user-supplied data. Successfully exploiting this issue may allow attackers to execute arbitrary machine code in the context of applications that use the affected library, but this has not been confirmed. Failed exploit attempts may crash applications, denying service to legitimate users. The vendor has released OpenSSL 0.9.8 f to address this issue. Some Nortel products contain this software as a component and thus are potentially affected by the vulnerabilities addressed. This bulletin provides a multi-product consolidated response for the Nortel products which are potentially affected. This bulletin addresses the following potential vulnerability: 1. CVE-2007-4995 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4995) Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allows remote attackers to execute arbitrary code via unspecified vectors. Before taking any action please ensure that you are viewing the latest official version of this security advisory by referencing http://www.nortel.com/securityadvisories
Type: Security Advisories
Number: 2008008923, Rev 1
Status: Retired
Date: 2008-12-01


Bulletin Downloads
Title Extension File Size Language
    Nortel Response to OpenSSL DTLS Heap Buffer Overflow Vulnerability
Checksum: 017eb8c43398117303f0e19789dc7547  [MD5]
[pdf] 25342 bytes English  




Associated Products
Alteon Switched Firewall 5400, 5600, and 5700
Application Server 5200
Bulletin temp product
CDMA Network Manager
CDMA Networks
CDMA Packet Data Serving Node (PDSN)
Communication Server 1000 Telephony Manager
Communication Server 1000E
Communication Server 1000M Cabinet/Chassis
Communication Server 1000S
Communication Server 2100
Contivity 2600 Secure IP Services Gateway
Contivity 4500 Secure IP Services Gateway
Contivity 4600 Secure IP Services Gateway
Ethernet Routing Switch 8600
Extended Peripheral Module (XPM)
Integrated Access - Cable
IP Address Domain Manager
Media Gateway 9000
Media Processing Server (MPS) 1000
Media Processing Server (MPS) 500
Meridian 1 Option 11C
Meridian 1 Option 11C Mini
Meridian 1 Option 51C, Option 61C, Option 81C
Mobile Location Center (MLC)
Multimedia Communication Server 5100
Multiservice Data Manager (MDM)
Packet Transit - IP
Periphonics Speech Platform
Self-Service Portfolio
Services Edge Router 5500
 
Speech and Self-Service
Switched Firewall 5100 Series
Switched Firewall 6000 Series
Threat Protection System 2050 Intrusion Sensor
Threat Protection System 2050 Threat Intelligence Sensor
Threat Protection System 2070 Defense Center
Threat Protection System 2070 Intrusion Sensor
Threat Protection System 2070 Threat Intelligence Sensor
Threat Protection System 2150 Intrusion Sensor
Threat Protection System 2170 Intrusion Sensor
Threat Protection System SEU/Rule Pack Updates
UMTS Networks
Universal Access - AAL1
Universal Access - IP
Universal Signaling Point
Universal Signaling Point Compact (USPc)
VoIP Infrastructure Solutions
VPN Gateway 3050
VPN Gateway 3070
VPN Router 200 Series
VPN Router 1010
VPN Router 1050
VPN Router 1100
VPN Router 1700
VPN Router 1740
VPN Router 1750
VPN Router 2700
VPN Router 5000
VPN Router Portfolio
Wireless Gateway 7250
Wireless Network Management System (W-NMS)