Nortel Response to Microsoft Security Bulletin MS08-071
| Description: |
On Tuesday, December 9, Microsoft released MS08-071 - Vulnerabilities in GDI Could Allow Remote Code Execution. This security update resolves two privately reported vulnerabilities in GDI. Exploitation of either of these vulnerabilities could allow remote code execution if a user opens a specially crafted WMF image file. Some Nortel products contain this software as a component and thus are potentially affected by the vulnerabilities addressed. This bulletin provides a multi-product consolidated response for the Nortel products which are potentially affected. This advisory addresses the following common vulnerability identifiers: 1. CVE-2008-2249: GDI Integer Overflow Vulnerability (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2249) A remote code execution vulnerability exists in the way that GDI handles integer calculations. The vulnerability could allow remote code execution if a user opens a specially crafted WMF image file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts. 2. CVE-2008-3465: GDI Heap Overflow Vulnerability (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3465) A remote code execution vulnerability exists in the way that GDI handles file size parameters in WMF files. The vulnerability could allow remote code execution if a third-party application uses a specific Microsoft API to copy a specially crafted WMF image file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts. Please refer to the Microsoft link in the Source section for additional information about workarounds and mitigating factors for the 3 vulnerabilities addressed by this update. MS08-071 replaces MS08-021. Microsoft Ratings for MS08-071: Maximum Sever |
| Type: |
Security Advisories |
| Number: |
2008009236, Rev 1 |
| Status: |
Retired |
| Date: |
2009-06-24 |