Back
Multimedia PC Client - Potential Vulnerability Due to Buffer Overflow
nortel.com
09/05/2008 12:00 UTC+1000
AUSCERT External Security Bulletin Redistribution
This is member-only content.
Some features are reserved for our members. For full access, please login or become a member.
Details
CVSS (Max)
Not Available
Products
XXXXXXXXXXXXXXXXXXXX
Publisher
Nortel
OS
Windows
Impact: Denial of Service
Access: Remote/Unauthenticated
CVE Names: CVE-2008-2080
Original Bulletin:
http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL&id=719698
- --------------------------BEGIN INCLUDED TEXT--------------------
Multimedia PC Client - Potential Vulnerability Due to Buffer Overflow
BULLETIN ID: 2008008799, Rev 1
PUBLISHED: 2008-04-30
STATUS: Active
REGION: All
PRIORITY: Critical
TYPE: Security Advisory
Source:
Nortel would like to acknowledge Parvez Anwar for bringing this
matter to Nortel's attention. Nortel welcomes and encourages
independent researchers to report any potential vulnerabilities via
Email <mailto:NNSATF@nortel.com> and will work with these parties
to assist in data validation to ensure responsible disclosure and
attribution.
Overview:
Nortel has been made aware of a potential vulnerability that may
cause the Multimedia PC Client to experience a Buffer Overflow -
Flooding the Multimedia PC Client with extraneous messaging can
result in the PC Client terminating with an error message. This may
also occur when scanning the Multimedia PC Client with the Nessus
(www.nessus.org) tool using the "Denial of Service" plug-in, and
it is called "Generic flood".
Before taking any action please ensure that you are viewing the
latest official version of this security advisory by referencing
http://www.nortel.com/securityadvisories
For more information: Please contact your next level of support or
visit http://www.nortel.com/contact for support numbers within your
region. Nortel security advisories: http://nortel.com/securityadvisories
Nortel Partner Information Center (PIC) website:
http://www.nortelnetworks.com/pic
Symptoms:
When the MultiMedia PC Client is flooded with extraneous messages
it can result in the application aborting.
Prevention:
This potential vulnerability can be prevented by upgrading to the
latest software as described in the Resolution section.
Mitigation:
There are no mitigation steps to address this vulnerability, as it
is resolved with a software update. See the Resolution section.
Risk:
This attack can cause a DoS type situation on the Multimedia PC
client and has been brought to Nortel's attention by Parvez Anwar.
To our knowledge, this attack has not been launched against any of
our customers.
CVE(s)
XXXXXXXXXXXXX