Welcome, Guest

Nortel Response to Apache 1.3 and 2.0 Web Server Daemon Vulnerabilities

Description: Before taking any action please ensure that you are viewing the latest official version of this security advisory by referencing http://www.nortel.com/securityadvisories Apache has recently provided fixes for the following issue: "Security Vulnerabilities in the Apache 1.3 and 2.0 Web Server Daemon and "mod_status" Module May Lead to Cross Site Scripting (XSS) or Denial of Service (DoS)." Some Nortel products contain this software as a component and thus are potentially affected by the vulnerabilities addressed. This bulletin provides a multi-product consolidated response for the Nortel products which are potentially affected. Following is a detailed description of the vulnerability: A vulnerability was reported in Apache mod_status. A remote user can conduct cross-site scripting attacks. The mod_status module does not properly filter HTML code from user-supplied input before displaying the input. A remote user can cause arbitrary scripting code to be executed by the target user's browser. The code will originate from the site running the Apache software and will run in the security context of that site. As a result, the code will be able to access the target user's cookies (including authentication cookies), if any, associated with the site, access data recently submitted by the target user via web form to the site, or take actions on the site acting as the target user. The impact is that a remote user can access the target user's cookies (including authentication cookies), if any, associated with the site running the Apache software, access data recently submitted by the target user via web form to the site, or take actions on the site acting as the target user.
Type: Security Advisories
Number: 2008008602, Rev 1
Status: Retired
Date: 2008-08-29


Bulletin Downloads
Title Extension File Size Language
    Nortel Response to Apache 1.3 and 2.0 Web Server Daemon Vulnerabilities
Checksum: aadf93283a03673d3fd73ba9a409e470  [MD5]
[pdf] 23946 bytes English  




Associated Products
Alteon Switched Firewall 5400, 5600, and 5700
BroadBand STP
Bulletin temp product
Business Communications Manager 200
Business Communications Manager 400
Business Communications Manager 50
CDMA Network Manager
CDMA Networks
CDMA SuperNode Data Manager
Circuit Switching
Communication Server 2000
Communication Server 2000 Core Manager
Communication Server 2000 Session Server Trunks
Communication Server 2000-Compact
Communication Server 2100
DMS-100 SSP
DMS-100/200 Local Switching Systems
DMS-250
DMS-500
DMS-Global Services Platform
DMS-STP
DMS-STP/SSP IntegratedNode (INode)
Enterprise Network Management System
Ethernet Routing Switch 8600
Extended Peripheral Module (XPM)
GSM Networks
GSM-UMTS Home Location Register
GSM-UMTS Mobile Switching Center Server
GSM-UMTS SuperNode Data Manager
Integrated Access - Cable
Integrated Element Management System (IEMS)
Media Gateway 9000
Media Processing Server (MPS) 100
 
Media Processing Server (MPS) 1000
Media Processing Server (MPS) 500
Meridian SL-100
Multiservice Data Manager (MDM)
Optivity Telephony Manager for SL-100
Packet Transit - AAL2
Packet Transit - IP
Packet Trunking - AAL1
Periphonics PeriToolsWorkstation
Periphonics Speech Platform
Self-Service Portfolio
Spectrum Peripheral Module (SPM)
Speech and Self-Service
SuperNode Data Manager
Survivable Remote Gateway (SRG) 50
Switched Firewall 5100 Series
Switched Firewall 6000 Series
Threat Protection System 2050 Intrusion Sensor
Threat Protection System 2050 Threat Intelligence Sensor
Threat Protection System 2070 Defense Center
Threat Protection System 2070 Intrusion Sensor
Threat Protection System 2070 Threat Intelligence Sensor
Threat Protection System 2150 Intrusion Sensor
Threat Protection System 2170 Intrusion Sensor
Threat Protection System SEU/Rule Pack Updates
UMTS Networks
Universal Access - AAL1
Universal Access - IP
VoIP Infrastructure Solutions
VPN Gateway 3050
VPN Gateway 3070
Wireless Network Management System (W-NMS)
XA-Core