Nortel Response to Microsoft Security Bulletin MS08-069
| Description: |
On Tuesday, Nov. 11, Microsoft released MS08-069 - Vulnerabilities in Microsoft XML Core Services Could Allow Remote Code Execution (955218). This security update resolves several vulnerabilities in Microsoft XML Core Services. The most severe vulnerability could allow remote code execution if a user viewed a specially crafted Web page using Internet Explorer. MS08-069 addresses the following 3 vulnerabilities: 1. CVE-2007-0099 - MSXML Memory Corruption Vulnerability - (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0099) A remote code execution vulnerability exists in the way that Microsoft XML Core Services parses XML content. The vulnerability could allow remote code execution if a user browses a Web site that contains specially crafted content or opens specially crafted HTML e-mail. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. 2. CVE-2008-4029 - MSXML DTD Cross-Domain Scripting Vulnerability - (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4029) An information disclosure vulnerability exists in the way that Microsoft XML Core Services handles error checks for external document type definitions (DTDs). The vulnerability could allow information disclosure if a user browses a Web site that contains specially crafted content or opens specially crafted HTML e-mail. An attacker who successfully exploited this vulnerability could read data from a Web page in another domain in Internet Explorer. In all cases, however, an attacker would have no way to force users to visit these Web sites. 3. CVE-2008-4033 - MSXML Header Request Vulnerability - (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4033) An information disclosure vulnerability exists in the way that Microsoft XML Core Services handles transfer-encoding headers. The vulnerability could allow i |
| Type: |
Security Advisories |
| Number: |
2008009187, Rev 1 |
| Status: |
Retired |
| Date: |
2009-04-29 |