Back

Multimedia PC Client - Potential Vulnerability Due to Buffer Overflow

nortel.com
09/05/2008 12:00 UTC+1000
AUSCERT External Security Bulletin Redistribution

This is member-only content.

Some features are reserved for our members. For full access, please login or become a member.

Details

CVSS (Max)
Not Available
Products
XXXXXXXXXXXXXXXXXXXX
Publisher
Nortel
OS
Windows Impact: Denial of Service Access: Remote/Unauthenticated CVE Names: CVE-2008-2080 Original Bulletin: http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=719698 - --------------------------BEGIN INCLUDED TEXT-------------------- Multimedia PC Client - Potential Vulnerability Due to Buffer Overflow BULLETIN ID: 2008008799, Rev 1 PUBLISHED: 2008-04-30 STATUS: Active REGION: All PRIORITY: Critical TYPE: Security Advisory Source: Nortel would like to acknowledge Parvez Anwar for bringing this matter to Nortel's attention. Nortel welcomes and encourages independent researchers to report any potential vulnerabilities via Email <mailto:NNSATF@nortel.com> and will work with these parties to assist in data validation to ensure responsible disclosure and attribution. Overview: Nortel has been made aware of a potential vulnerability that may cause the Multimedia PC Client to experience a Buffer Overflow - Flooding the Multimedia PC Client with extraneous messaging can result in the PC Client terminating with an error message. This may also occur when scanning the Multimedia PC Client with the Nessus (www.nessus.org) tool using the "Denial of Service" plug-in, and it is called "Generic flood". Before taking any action please ensure that you are viewing the latest official version of this security advisory by referencing http://www.nortel.com/securityadvisories For more information: Please contact your next level of support or visit http://www.nortel.com/contact for support numbers within your region. Nortel security advisories: http://nortel.com/securityadvisories Nortel Partner Information Center (PIC) website: http://www.nortelnetworks.com/pic Symptoms: When the MultiMedia PC Client is flooded with extraneous messages it can result in the application aborting. Prevention: This potential vulnerability can be prevented by upgrading to the latest software as described in the Resolution section. Mitigation: There are no mitigation steps to address this vulnerability, as it is resolved with a software update. See the Resolution section. Risk: This attack can cause a DoS type situation on the Multimedia PC client and has been brought to Nortel's attention by Parvez Anwar. To our knowledge, this attack has not been launched against any of our customers.
CVE(s)
XXXXXXXXXXXXX