Nortel Response to Microsoft Security Bulletin MS08-037
| Description: |
On July 08, 2008, Microsoft released a security update MS08-037 - Vulnerabilities in DNS Could Allow Spoofing (953230). Also, on July 25th, Microsoft released Microsoft Security Advisory (956187) - Increased Threat for DNS Spoofing Vulnerability. Some Nortel products contain this software as a component and thus are potentially affected by the vulnerabilities addressed. This bulletin provides a multi-product consolidated response for the Nortel products which are potentially affected. This advisory addresses the following Common Vulnerability IDs (CVEs): 1) DNS Insufficient Socket Entropy Vulnerability - CVE-2008-1447 (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447) A spoofing vulnerability exists in Windows DNS client and Windows DNS server. This vulnerability could allow a remote unauthenticated attacker to quickly and reliably spoof responses and insert records into the DNS server or client cache, thereby redirecting Internet traffic. 2) DNS Cache Poisoning Vulnerability - CVE-2008-1454 (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1454) A cache poisoning vulnerability exists in Windows DNS Server. The vulnerability could allow an unauthenticated remote attacker to send specially crafted responses to DNS requests made by vulnerable systems, thereby poisoning the DNS cache and redirecting Internet traffic from legitimate locations. Impact of Vulnerability: Spoofing Maximum Severity Rating: Critical Before taking any action please ensure that you are viewing the latest official version of this security advisory by referencing http://www.nortel.com/securityadvisories For more information: Please contact your next level of support or visit http://www.nortel.com/contact for support numbers within your region. Nortel security advisories: http://nortel.com/securityadvisories Nortel Partner Information Center (PIC) website: http://www.nortelnetworks.com/pic |
| Type: |
Security Advisories |
| Number: |
2008008989, Rev 1 |
| Status: |
Retired |
| Date: |
2008-08-21 |