CERTA-2007-AVI-448
Vulnerability from certfr_avis
Plusieurs vulnérabilités touchant des produits Nortel sont corrigées.
Description
Plusieurs vulnérabilités touchant des produits Nortel pour la VoIP (Voice Over IP) permettent d'écouter les conversations et de provoquer des dénis de service à distance. Elles sont corrigées dans les dernières mises à jour.
Solution
Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).
Logiciels affectés :
- Nortel IP Softphone 2050 ;
- Nortel IP Softphone 2050 ;
- Nortel Mobile Voice Client 2050 ;
- Nortel Multimedia Communication Server 5100 3.x ;
- Nortel Multimedia Communication Server 5100 4.x.
Système d'exploitation affecté :
- Nortel Centrex IP Client Manager (CICM).
Boitiers affectés :
- Nortel Audio Conference Phone 2033 ;
- Nortel Business Communications Manager 3.x ;
- Nortel Business Communications Manager 4.x ;
- Nortel Business Communications Manager 50 ;
- Nortel Communication Server 1000 ;
- Nortel IP Phone 1100 Series ;
- Nortel IP Phone 2000 Series ;
- Nortel Multimedia Communication Server 5100.
Impacted products
| Vendor | Product | Description |
|---|
References
| Title | Publication Time | Tags | |
|---|---|---|---|
{
"$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
"affected_systems": [],
"affected_systems_content": "\u003cP\u003eLogiciels affect\u00e9s :\u003c/P\u003e \u003cUL\u003e \u003cLI\u003eNortel IP Softphone 2050 ;\u003c/LI\u003e \u003cLI\u003eNortel IP Softphone 2050 ;\u003c/LI\u003e \u003cLI\u003eNortel Mobile Voice Client 2050 ;\u003c/LI\u003e \u003cLI\u003eNortel Multimedia Communication Server 5100 3.x ;\u003c/LI\u003e \u003cLI\u003eNortel Multimedia Communication Server 5100 4.x.\u003c/LI\u003e \u003c/UL\u003e \u003cP\u003eSyst\u00e8me d\u0027exploitation affect\u00e9 :\u003c/P\u003e \u003cUL\u003e \u003cLI\u003eNortel Centrex IP Client Manager (CICM).\u003c/LI\u003e \u003c/UL\u003e \u003cP\u003eBoitiers affect\u00e9s :\u003c/P\u003e \u003cUL\u003e \u003cLI\u003eNortel Audio Conference Phone 2033 ;\u003c/LI\u003e \u003cLI\u003eNortel Business Communications Manager 3.x ;\u003c/LI\u003e \u003cLI\u003eNortel Business Communications Manager 4.x ;\u003c/LI\u003e \u003cLI\u003eNortel Business Communications Manager 50 ;\u003c/LI\u003e \u003cLI\u003eNortel Communication Server 1000 ;\u003c/LI\u003e \u003cLI\u003eNortel IP Phone 1100 Series ;\u003c/LI\u003e \u003cLI\u003eNortel IP Phone 2000 Series ;\u003c/LI\u003e \u003cLI\u003eNortel Multimedia Communication Server 5100.\u003c/LI\u003e \u003c/UL\u003e",
"content": "## Description\n\nPlusieurs vuln\u00e9rabilit\u00e9s touchant des produits Nortel pour la VoIP\n(Voice Over IP) permettent d\u0027\u00e9couter les conversations et de provoquer\ndes d\u00e9nis de service \u00e0 distance. Elles sont corrig\u00e9es dans les derni\u00e8res\nmises \u00e0 jour.\n\n## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
"cves": [],
"initial_release_date": "2007-10-19T00:00:00",
"last_revision_date": "2007-10-19T00:00:00",
"links": [
{
"title": "Bulletins de s\u00e9curit\u00e9 Nortel 654641 et 654714 du 17 octobre 2007 :",
"url": "http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL\u0026id=654641"
},
{
"title": "Bulletins de s\u00e9curit\u00e9 Nortel 654641 et 654714 du 17 octobre 2007 :",
"url": "http://support.nortel.com/go/main.jsp?cscat=BLTNDETAIL\u0026id=654714"
}
],
"reference": "CERTA-2007-AVI-448",
"revisions": [
{
"description": "version initiale.",
"revision_date": "2007-10-19T00:00:00.000000"
}
],
"risks": [
{
"description": "D\u00e9ni de service \u00e0 distance"
},
{
"description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es (\u00e9coute)"
}
],
"summary": "Plusieurs vuln\u00e9rabilit\u00e9s touchant des produits Nortel sont corrig\u00e9es.\n",
"title": "Multiples vuln\u00e9rabilit\u00e9s dans des produits Nortel",
"vendor_advisories": [
{
"published_at": null,
"title": "Bulletins de s\u00e9curit\u00e9 Nortel 654641 et 654714 du 17 octobre 2007",
"url": null
}
]
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…