Welcome, Guest

Nortel Response to Adobe Reader Vulnerabilities (APSA08-01)

Description: Adobe has recently released fixes for multiple vulnerabilities that exist in Adobe Reader and Adobe Acrobat Professional when viewing PDFs. Some Nortel products contain this software as a component any may be affected. This bulletin provides a multi-product consolidated response for the Nortel products which are potentially affected by these vulnerabilities. The Adobe security advisory is available at: http://www.adobe.com/support/security/advisories/apsa08-01.html Before taking any action please ensure that you are viewing the latest official version of this security advisory by referencing http://www.nortel.com/securityadvisories Some of the issues addressed by apsa08-01 have unknown impacts while others can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a user's system. Following is an overview of the vulnerabilities: 1) Multiple boundary errors in several unspecified JavaScript methods can be exploited to cause stack-based buffer overflows via a specially crafted .PDF file. Successful exploitation allows execution of arbitrary code. 2) An unspecified insecure JavaScript method in EScript.api can be exploited to execute arbitrary code via a specially crafted .PDF file. 3) An error in the loading of "Security Provider" libraries can be exploited to execute arbitrary code by e.g. tricking a user into opening a .PDF file in a directory that contains a malicious library with the same filename as a "Security Provider" library. 4) The insecure JavaScript method "DOC.print()" can be exploited to silently print a specially crafted PDF file. Other vulnerabilities also exist, for which no details are currently available. The vulnerabilities affect the following versions: * Adobe Reader 8.1.1 and earlier * Adobe Acrobat Professional, 3D and Standard 8.1.1 and earlier For more information: Please contact your next level of support or visit http://www.nortel.com/contact for support numbers within your region. Nortel securi
Type: Security Advisories
Number: 2008008642, Rev 1
Status: Retired
Date: 2008-07-03


Bulletin Downloads
Title Extension File Size Language
    Nortel Response to Adobe Reader Vulnerabilities (APSA08-01)
Checksum: 38a62633a38972b4d5de80f991e5c66d  [MD5]
[pdf] 22139 bytes English  




Associated Products
BroadBand STP
Business Communications Manager 200
Business Communications Manager 400
Business Communications Manager 1000
CDMA Network Manager
CDMA Networks
CDMA SuperNode Data Manager
Circuit Switching
Communication Server 2000
Communication Server 2000 Core Manager
Communication Server 2000 Session Server Trunks
Communication Server 2000-Compact
Communication Server 2100
DMS-100 SSP
DMS-100/200 Local Switching Systems
DMS-250
DMS-500
DMS-Global Services Platform
DMS-STP
DMS-STP/SSP IntegratedNode (INode)
Extended Peripheral Module (XPM)
GSM Networks
 
GSM-UMTS Home Location Register
GSM-UMTS Mobile Switching Center Server
GSM-UMTS SuperNode Data Manager
Integrated Access - Cable
Integrated Element Management System (IEMS)
Media Processing Server (MPS) 1000
Media Processing Server (MPS) 500
Meridian SL-100
Optivity Telephony Manager for SL-100
Packet Transit - AAL2
Packet Transit - IP
Packet Trunking - AAL1
Periphonics Speech Platform
Self-Service Portfolio
Spectrum Peripheral Module (SPM)
Speech and Self-Service
SuperNode Data Manager
UMTS Networks
Universal Access - AAL1
Universal Access - IP
Wireless Network Management System (W-NMS)
XA-Core