Welcome, Guest

Nortel Response to 2 Potential DoS Vulnerabilities in OpenSSL

Description: Two vulnerabilities have been reported in OpenSSL, which can be exploited by malicious people to cause a DoS (Denial of Service). Some Nortel products contain this software as a component and thus are potentially affected by the vulnerabilities addressed. This bulletin provides a multi-product consolidated response for the Nortel products which are potentially affected. This bulletin addresses the following potential vulnerabilities: 1) CVE-2008-0891 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0891) Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a crafted packet. NOTE: some of these details are obtained from third party information. 2) CVE-2008-1672 (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1672) OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites." Before taking any action please ensure that you are viewing the latest official version of this security advisory by referencing http://www.nortel.com/securityadvisories
Type: Security Advisories
Number: 2008008922, Rev 2
Status: Retired
Date: 2008-08-06


Bulletin Downloads
Title Extension File Size Language
    Nortel Response to 2 Potential DoS Vulnerabilities in OpenSSL
Checksum: 2e748514350960306fcbf55e4a809807  [MD5]
[pdf] 25767 bytes English  




Associated Products
Alteon Switched Firewall 5400, 5600, and 5700
Application Server 5200
Bulletin temp product
CDMA Network Manager
CDMA Networks
CDMA Packet Data Serving Node (PDSN)
Communication Server 1000 Telephony Manager
Communication Server 1000E
Communication Server 1000M Cabinet/Chassis
Communication Server 1000S
Communication Server 2100
Contivity 2600 Secure IP Services Gateway
Contivity 4500 Secure IP Services Gateway
Contivity 4600 Secure IP Services Gateway
Ethernet Routing Switch 8600
Extended Peripheral Module (XPM)
Integrated Access - Cable
IP Address Domain Manager
Media Gateway 9000
Media Processing Server (MPS) 1000
Media Processing Server (MPS) 500
Meridian 1 Option 11C
Meridian 1 Option 11C Mini
Meridian 1 Option 51C, Option 61C, Option 81C
Mobile Location Center (MLC)
Multimedia Communication Server 5100
Multiservice Data Manager (MDM)
Packet Transit - IP
Periphonics Speech Platform
Self-Service Portfolio
Services Edge Router 5500
 
Speech and Self-Service
Switched Firewall 5100 Series
Switched Firewall 6000 Series
Threat Protection System 2050 Intrusion Sensor
Threat Protection System 2050 Threat Intelligence Sensor
Threat Protection System 2070 Defense Center
Threat Protection System 2070 Intrusion Sensor
Threat Protection System 2070 Threat Intelligence Sensor
Threat Protection System 2150 Intrusion Sensor
Threat Protection System 2170 Intrusion Sensor
Threat Protection System SEU/Rule Pack Updates
UMTS Networks
Universal Access - AAL1
Universal Access - IP
Universal Signaling Point
Universal Signaling Point Compact (USPc)
VoIP Infrastructure Solutions
VPN Gateway 3050
VPN Gateway 3070
VPN Router 200 Series
VPN Router 1010
VPN Router 1050
VPN Router 1100
VPN Router 1700
VPN Router 1740
VPN Router 1750
VPN Router 2700
VPN Router 5000
VPN Router Portfolio
Wireless Gateway 7250
Wireless Network Management System (W-NMS)