Nortel Response to Microsoft Security Bulletin MS09-039
| Description: |
On Tuesday August 11th, Microsoft released MS09-039 - Vulnerabilities in WINS Could Allow Remote Code Execution (969883). This security update resolves two privately reported vulnerabilities in the Windows Internet Name Service (WINS). Either vulnerability could allow remote code execution if a user received a specially crafted WINS replication packet on an affected system running the WINS service. By default, WINS is not installed on any affected operating system version. Only customers who manually install this component are affected by this issue. Some Nortel products contain this Microsoft software as a component and thus are potentially affected by the vulnerability. This bulletin contains a consolidated, multi-product response to the Microsoft update. MS09-039 addresses the following CVEs: 1) WINS Heap Overflow Vulnerability - CVE-2009-1923 (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1923) A remote code execution vulnerability exists in the Windows Internet Name Service (WINS) due to a buffer overflow caused by incorrect calculation of buffer length when processing specially crafted WINS network packets. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts. 2) WINS Integer Overflow Vulnerability - CVE-2009-1924 (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1924) A remote code execution vulnerability exists in the default configuration of the Windows Internet Name Service (WINS) due to insufficient validation of data structures within specially crafted WINS network packets received from a trusted WINS replication partner. Microsoft ratings for MS09-039: Maximum Severity Rating - Critical Impact of Vulnerability - Remote Code Execution Exploitability Index - 1 - Consistent exploit code likely. Microsoft bulletins replaced by this update: MS09-008. Before taking any action ple |
| Type: |
Security Advisories |
| Number: |
2009009665, Rev 1 |
| Status: |
Active |
| Date: |
2009-08-14 |