Welcome, Guest

Nortel Response to Microsoft Security Bulletin MS08-073

Description: On Tuesday, December 9, Microsoft released MS08-073 - Cumulative Security Update for Internet Explorer. This security update resolves four privately reported vulnerabilities. The vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. Some Nortel products contain this software as a component. This bulletin provides a multi-product consolidated response for the Nortel products which are potentially affected. MS08-073 addresses the following 4 vulnerabilities: 1. CVE-2008-4258 - Parameter Validation Memory Corruption Vulnerability (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4258) A remote code execution vulnerability exists in the way Internet Explorer handles certain navigation methods. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. 2. CVE-2008-4259 - HTML Objects Memory Corruption Vulnerability (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4259) A remote code execution vulnerability exists in Internet Explorer due to attempts to access uninitialized memory in certain situations. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. 3. CVE-2008-4260 - Uninitialized Memory Corruption Vulnerability (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4260) A remote code execution vulnerability exists in the way Internet Explorer accesses an object that has been deleted. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vuln
Type: Security Advisories
Number: 2008009237, Rev 1
Status: Retired
Date: 2009-06-24


Bulletin Downloads
Title Extension File Size Language
    Nortel Response to Microsoft Security Bulletin MS08-073
Checksum: 276021b7b9ef39dbbb3b66f3abbe88cb  [MD5]
[pdf] 23368 bytes English  




Associated Products
Application Server 5200
CallPilot
Communication Server 1000 Telephony Manager
Contact Center - Express
Contact Center - Multimedia
Contact Center Manager Administration
Contact Center Manager Server
Contact Center Portfolio
Integrated Access - Cable
Media Processing Server (MPS) 100
Media Processing Server (MPS) 1000
Media Processing Server (MPS) 500
Multimedia Communication Server 5100
 
Multiservice Data Manager (MDM)
Packet Transit - IP
Periphonics PeriToolsWorkstation
Periphonics Speech Platform
Self-Service Portfolio
Speech and Self-Service
UMTS Networks
Universal Access - IP
VoIP Infrastructure Solutions
VPN Client
VPN Router Portfolio
WiMAX Network Management System 5000
Wireless Network Management System (W-NMS)