Product Affected

All domestic releases of JUNOS Internet software released prior to August 5, 2002 are affected.
Low

Problem

Several security vulnerabilities exist in current releases of the OpenSSL shared library code, which is included with domestic releases of JUNOS software. Details of these security vulnerabilities can be found at http://www.openssl.org/news/secadv_20020730.txt and are documented in PR/26985.

Note: Operating system software on the G10 cable modem termination system (CMTS) is unaffected by these security vulnerabilities.

Solution

The OpenSSL code shipped with domestic releases of JUNOS software has been patched to eliminate these vulnerabilities.

New releases of JUNOS software containing the patched OpenSSL code will be available as soon as possible. Customers should upgrade their software to a release issued after August 5, 2002.

Severity Assessment

JUNOS software contains only one of the vulnerabilities identified. Data could possibly be corrupted if the router attempts to verify a malformed certificate supplied by the server. The likelihood of this occurring is very low.