Welcome, Guest

Nortel Response to Microsoft Security Bulletin MS08-031

Description: On June 10, 2008, Microsoft released a security update MS08-031 -Cumulative Security Update for Internet Explorer (950759). Some Nortel products contain this software as a component and thus are potentially affected by the vulnerabilities addressed. This bulletin provides a multi-product consolidated response for the Nortel products which are potentially affected. MS08-031 addresses the following potential vulnerabilities: 1) CVE-2008-1442 (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1442) HTML Objects Memory Corruption Vulnerability A remote code execution vulnerability exists in the way Internet Explorer displays a Web page that contains certain unexpected method calls to HTML objects. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. 2) CVE-2008-1544 (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1544) Request Header Cross-Domain Information Disclosure Vulnerability An information disclosure vulnerability exists in the way Internet Explorer handles certain request headers. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow the attacker to read data from another Internet Explorer domain. Impact of Vulnerability: Remote Code Execution Maximum Severity Rating: Critical Before taking any action please ensure that you are viewing the latest official version of this security advisory by referencing http://www.nortel.com/securityadvisories For more information: Please contact your next level of support or visit http://www.nortel.com/contact for support numbers within your region. Nortel security advisories: http://nortel.com/securityadvisories Nortel Partner Information Center (PIC) website: http://www
Type: Security Advisories
Number: 2008008896, Rev 1
Status: Retired
Date: 2008-10-17


Bulletin Downloads
Title Extension File Size Language
    Nortel Response to Microsoft Security Bulletin MS08-031
Checksum: a669be463fb53768bcfb30fd00466348  [MD5]
[pdf] 21456 bytes English  




Associated Products
Application Server 5200
CallPilot
CDMA Network Manager
CDMA Networks
Communication Server 1000 Telephony Manager
Contact Center - Express
Contact Center - Multimedia
Contact Center Manager Administration
Contact Center Manager Server
Contact Center Portfolio
Integrated Access - Cable
Media Processing Server (MPS) 1000
 
Media Processing Server (MPS) 500
Multimedia Communication Server 5100
Multiservice Data Manager (MDM)
Packet Transit - IP
Periphonics PeriToolsWorkstation
Periphonics Speech Platform
Self-Service Portfolio
Speech and Self-Service
UMTS Networks
Universal Access - IP
VoIP Infrastructure Solutions
Wireless Network Management System (W-NMS)