Nortel Response to Microsoft Security Bulletin MS08-073
| Description: |
On Tuesday, December 9, Microsoft released MS08-073 - Cumulative Security Update for Internet Explorer. This security update resolves four privately reported vulnerabilities. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Some Nortel products contain this software as a component. This bulletin provides a multi-product consolidated response for the Nortel products which are potentially affected. MS08-073 addresses the following 4 vulnerabilities: 1. CVE-2008-4258 - Parameter Validation Memory Corruption Vulnerability (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4258) A remote code execution vulnerability exists in the way Internet Explorer handles certain navigation methods. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. 2. CVE-2008-4259 - HTML Objects Memory Corruption Vulnerability (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4259) A remote code execution vulnerability exists in Internet Explorer due to attempts to access uninitialized memory in certain situations. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. 3. CVE-2008-4260 - Uninitialized Memory Corruption Vulnerability (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4260) A remote code execution vulnerability exists in the way Internet Explorer accesses an object that has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vuln |
| Type: |
Security Advisories |
| Number: |
2008009237, Rev 1 |
| Status: |
Retired |
| Date: |
2009-06-24 |